İçeriğe atla
Noroxi

matomo kayıtları

matomo üreticisine ait 25 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

25 kayıt
  • CVE-2009-4140
    53Planlayın

    Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0

    YüksekCVSS 7,5SilahlaştırılmışEPSS %76

    teethgrinder.co.uk · open flash chart22 Ara 2009

  • CVE-2020-29578
    40Planlayın

    The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user.

    KritikCVSS 9,8İstismar yokEPSS %2

    matomo · piwik fpm-alpine docker image8 Ara 2020

  • CVE-2009-4137
    35İzleyin

    The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the

    YüksekCVSS 7,5Kavram kanıtıEPSS %17

    matomo · matomo24 Ara 2009

  • CVE-2015-7816
    31İzleyin

    The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object inj

    YüksekCVSS 7,5İstismar yokEPSS %4

    matomo · matomo16 Kas 2015

  • CVE-2015-7815
    31İzleyin

    Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute ar

    YüksekCVSS 7,5İstismar yokEPSS %3

    matomo · matomo16 Kas 2015

  • CVE-2010-2786
    28İzleyin

    Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unsp

    OrtaCVSS 6,8İstismar yokEPSS %3

    matomo · matomo2 Ağu 2010

  • CVE-2011-4941
    28İzleyin

    Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown at

    OrtaCVSS 6,8İstismar yokEPSS %2

    matomo · matomo18 Eyl 2012

  • CVE-2011-0398
    25İzleyin

    The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to byp

    OrtaCVSS 6,4İstismar yokEPSS %1

    matomo · matomo10 Oca 2011

  • CVE-2013-0195
    24İzleyin

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    OrtaCVSS 6,1İstismar yokEPSS %1

    matomo · matomo20 Kas 2019

  • CVE-2013-0194
    24İzleyin

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    OrtaCVSS 6,1İstismar yokEPSS %1

    matomo · matomo20 Kas 2019

  • CVE-2013-0193
    24İzleyin

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    OrtaCVSS 6,1İstismar yokEPSS %1

    matomo · matomo20 Kas 2019

  • CVE-2022-33156
    24İzleyin

    The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    matomo · integration12 Tem 2022

  • CVE-2023-6923
    24İzleyin

    Matomo <= 4.15.3 - Reflected Cross-Site Scripting via idsite

    OrtaCVSS 6,1İstismar yokEPSS %1

    matomo · matomo28 Şub 2024

  • CVE-2011-0401
    20İzleyin

    Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denia

    OrtaCVSS 5,0İstismar yokEPSS %2

    matomo · matomo10 Oca 2011

  • CVE-2011-0400
    20İzleyin

    Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote att

    OrtaCVSS 5,0İstismar yokEPSS %1

    matomo · matomo10 Oca 2011

  • CVE-2011-3791
    20İzleyin

    Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i

    OrtaCVSS 5,0İstismar yokEPSS %1

    matomo · matomo23 Eyl 2011

  • CVE-2009-1085
    20İzleyin

    Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to

    OrtaCVSS 5,0İstismar yokEPSS %1

    matomo · matomo25 Mar 2009

  • CVE-2013-2633
    20İzleyin

    Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to ob

    OrtaCVSS 5,0İstismar yokEPSS %1

    matomo · matomo21 Mar 2013

  • CVE-2025-4415
    19İzleyin

    Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058

    OrtaCVSS 4,8İstismar yokEPSS %0

    matomo · piwik pro21 May 2025

  • CVE-2010-1453
    18İzleyin

    Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web scri

    OrtaCVSS 4,3Kavram kanıtıEPSS %3

    piwik · piwik7 May 2010

  • CVE-2011-0004
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via un

    OrtaCVSS 4,3İstismar yokEPSS %2

    matomo · matomo10 Oca 2011

  • CVE-2011-0399
    17İzleyin

    Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for r

    OrtaCVSS 4,3İstismar yokEPSS %1

    matomo · matomo10 Oca 2011

  • CVE-2019-12215
    17İzleyin

    A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path o

    OrtaCVSS 4,3İstismar yokEPSS %1

    matomo · matomo20 May 2019

  • CVE-2012-4541
    17İzleyin

    Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified

    OrtaCVSS 4,3İstismar yokEPSS %1

    matomo · matomo19 Kas 2012

  • CVE-2013-1844
    17İzleyin

    Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via unspecified

    OrtaCVSS 4,3İstismar yokEPSS %1

    matomo · matomo21 Mar 2013