njtech kayıtları
njtech üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2018-11670Kavram kanıtı | An issue was discovered in GreenCMS v2.3.0603.njtech · greencms · CWE-352 | Yüksek8,8 | — | %2,5 | 1 Haz 2018 |
36İzleyin | CVE-2018-11671Kavram kanıtı | An issue was discovered in GreenCMS v2.3.0603.njtech · greencms · CWE-352 | Yüksek8,8 | — | %2,5 | 1 Haz 2018 |
34İzleyin | CVE-2018-12604Kavram kanıtı | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.njtech · greencms · CWE-532 | Yüksek7,5 | — | %13,2 | 20 Haz 2018 |
32İzleyin | CVE-2022-28918İstismar yok | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugnjtech · greencms | Yüksek8,1 | — | %1,1 | 26 Nis 2022 |
32İzleyin | CVE-2020-21366İstismar yok | Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.njtech · greencms · CWE-352 | Yüksek8,0 | — | %0,3 | 20 Haz 2023 |
28İzleyin | CVE-2019-25574İstismar yok | Green CMS 2.x Path Traversal Arbitrary File Downloadnjtech · greencms · CWE-22 | Yüksek7,1 | — | %1,1 | 21 Mar 2026 |
28İzleyin | CVE-2019-25573İstismar yok | Green CMS 2.x SQL Injection via cat Parameternjtech · greencms · CWE-89 | Yüksek7,1 | — | %0,3 | 21 Mar 2026 |
21İzleyin | CVE-2024-22570İstismar yok | A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbnjtech · greencms · CWE-79 | Orta5,4 | — | %0,3 | 29 Oca 2024 |
8İzleyin | CVE-2025-15187İstismar yok | GreenCMS File DataController.class.php path traversalnjtech · greencms · CWE-22 | Düşük2,0 | — | %0,7 | 29 Ara 2025 |
8İzleyin | CVE-2025-9415İstismar yok | GreenCMS index.php unrestricted uploadnjtech · greencms · CWE-284 | Düşük2,1 | — | %0,4 | 25 Ağu 2025 |
7İzleyin | CVE-2025-14244İstismar yok | GreenCMS Menu Management CustomController.class.php cross site scriptingnjtech · greencms · CWE-79 | Düşük1,9 | — | %0,3 | 8 Ara 2025 |
- CVE-2018-1167036İzleyin
An issue was discovered in GreenCMS v2.3.0603.
YüksekCVSS 8,8Kavram kanıtıEPSS %2njtech · greencms1 Haz 2018
- CVE-2018-1167136İzleyin
An issue was discovered in GreenCMS v2.3.0603.
YüksekCVSS 8,8Kavram kanıtıEPSS %2njtech · greencms1 Haz 2018
- CVE-2018-1260434İzleyin
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
YüksekCVSS 7,5Kavram kanıtıEPSS %13njtech · greencms20 Haz 2018
- CVE-2022-2891832İzleyin
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plug
YüksekCVSS 8,1İstismar yokEPSS %1njtech · greencms26 Nis 2022
- CVE-2020-2136632İzleyin
Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.
YüksekCVSS 8,0İstismar yokEPSS %0njtech · greencms20 Haz 2023
- CVE-2019-2557428İzleyin
Green CMS 2.x Path Traversal Arbitrary File Download
YüksekCVSS 7,1İstismar yokEPSS %1njtech · greencms21 Mar 2026
- CVE-2019-2557328İzleyin
Green CMS 2.x SQL Injection via cat Parameter
YüksekCVSS 7,1İstismar yokEPSS %0njtech · greencms21 Mar 2026
- CVE-2024-2257021İzleyin
A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arb
OrtaCVSS 5,4İstismar yokEPSS %0njtech · greencms29 Oca 2024
- CVE-2025-151878İzleyin
GreenCMS File DataController.class.php path traversal
DüşükCVSS 2,0İstismar yokEPSS %1njtech · greencms29 Ara 2025
- CVE-2025-94158İzleyin
GreenCMS index.php unrestricted upload
DüşükCVSS 2,1İstismar yokEPSS %0njtech · greencms25 Ağu 2025
- CVE-2025-142447İzleyin
GreenCMS Menu Management CustomController.class.php cross site scripting
DüşükCVSS 1,9İstismar yokEPSS %0njtech · greencms8 Ara 2025