kunena kayıtları
kunena üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-11020İstismar yok | Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png.kunena · kunena · CWE-434 | Kritik9,8 | — | %2,9 | 25 Şub 2020 |
30İzleyin | CVE-2012-4868İstismar yok | SQL injection vulnerability in news.php in the Kunena component 1.7.2 for Joomla! allows remote attackers to execute arbitrary SQL commands kunena · kunena · CWE-89 | Yüksek7,5 | — | %1,2 | 6 Eyl 2012 |
30İzleyin | CVE-2009-4550Kavram kanıtı | SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrjoomla · joomla\! · CWE-89 | Yüksek7,5 | — | %1,0 | 4 Oca 2010 |
26İzleyin | CVE-2014-9102İstismar yok | Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrarkunena · kunena · CWE-89 | Orta6,5 | — | %1,7 | 26 Kas 2014 |
24İzleyin | CVE-2017-5673İstismar yok | In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS.kunena · kunena · CWE-79 | Orta6,1 | — | %0,7 | 22 Mar 2017 |
21İzleyin | CVE-2019-15120Kavram kanıtı | The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.kunena · kunena · CWE-79 | Orta5,4 | — | %1,4 | 16 Ağu 2019 |
18İzleyin | CVE-2014-9103İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrkunena · kunena · CWE-79 | Orta4,3 | — | %1,9 | 26 Kas 2014 |
- CVE-2016-1102040Planlayın
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png.
KritikCVSS 9,8İstismar yokEPSS %3kunena · kunena25 Şub 2020
- CVE-2012-486830İzleyin
SQL injection vulnerability in news.php in the Kunena component 1.7.2 for Joomla! allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1kunena · kunena6 Eyl 2012
- CVE-2009-455030İzleyin
SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitr
YüksekCVSS 7,5Kavram kanıtıEPSS %1joomla · joomla\!4 Oca 2010
- CVE-2014-910226İzleyin
Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrar
OrtaCVSS 6,5İstismar yokEPSS %2kunena · kunena26 Kas 2014
- CVE-2017-567324İzleyin
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS.
OrtaCVSS 6,1İstismar yokEPSS %1kunena · kunena22 Mar 2017
- CVE-2019-1512021İzleyin
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
OrtaCVSS 5,4Kavram kanıtıEPSS %1kunena · kunena16 Ağu 2019
- CVE-2014-910318İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitr
OrtaCVSS 4,3İstismar yokEPSS %2kunena · kunena26 Kas 2014