ofcms project kayıtları
ofcms project üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-34256İstismar yok | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.ofcms project · ofcms · CWE-89 | Kritik9,8 | — | %0,7 | 14 May 2024 |
36İzleyin | CVE-2019-9617İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-434 | Yüksek8,8 | — | %2,7 | 6 Mar 2019 |
36İzleyin | CVE-2019-9609İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-434 | Yüksek8,8 | — | %2,7 | 6 Mar 2019 |
36İzleyin | CVE-2019-9608İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-434 | Yüksek8,8 | — | %2,7 | 6 Mar 2019 |
36İzleyin | CVE-2019-9612İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-434 | Yüksek8,8 | — | %2,7 | 6 Mar 2019 |
36İzleyin | CVE-2019-9614İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-74 | Yüksek8,8 | — | %2,6 | 6 Mar 2019 |
35İzleyin | CVE-2023-24760İstismar yok | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.ofcms project · ofcms · CWE-269 | Yüksek8,8 | — | %0,8 | 15 Mar 2023 |
29İzleyin | CVE-2019-9616İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-706 | Yüksek7,2 | — | %2,7 | 6 Mar 2019 |
29İzleyin | CVE-2019-9613İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-434 | Yüksek7,2 | — | %2,7 | 6 Mar 2019 |
28İzleyin | CVE-2019-9615İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-89 | Yüksek7,2 | — | %1,3 | 6 Mar 2019 |
26İzleyin | CVE-2019-9611İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-22 | Orta6,5 | — | %1,4 | 6 Mar 2019 |
26İzleyin | CVE-2024-48235İstismar yok | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.ofcms project · ofcms · CWE-94 | Orta6,5 | — | %0,7 | 25 Eki 2024 |
26İzleyin | CVE-2024-48236İstismar yok | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of tofcms project · ofcms · CWE-94 | Orta6,5 | — | %0,7 | 25 Eki 2024 |
24İzleyin | CVE-2022-29653İstismar yok | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.ofcms project · ofcms · CWE-79 | Orta6,1 | — | %0,6 | 2 Haz 2022 |
21İzleyin | CVE-2022-27960İstismar yok | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarilofcms project · ofcms · CWE-276 | Orta5,4 | — | %0,5 | 10 Nis 2022 |
21İzleyin | CVE-2023-51807İstismar yok | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the titofcms project · ofcms · CWE-79 | Orta5,4 | — | %0,5 | 16 Oca 2024 |
21İzleyin | CVE-2022-27961İstismar yok | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML ofcms project · ofcms · CWE-79 | Orta5,4 | — | %0,4 | 10 Nis 2022 |
21İzleyin | CVE-2024-9411İstismar yok | OFCMS add.json add cross site scriptingofcms project · ofcms · CWE-79 | Orta5,3 | — | %0,4 | 1 Eki 2024 |
21İzleyin | CVE-2025-1557İstismar yok | OFCMS cross-site request forgeryofcms project · ofcms · CWE-352 | Orta5,3 | — | %0,3 | 22 Şub 2025 |
17İzleyin | CVE-2019-9610İstismar yok | An issue was discovered in OFCMS before 1.1.3.ofcms project · ofcms · CWE-22 | Orta4,3 | — | %1,4 | 6 Mar 2019 |
- CVE-2024-3425639İzleyin
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
KritikCVSS 9,8İstismar yokEPSS %1ofcms project · ofcms14 May 2024
- CVE-2019-961736İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 8,8İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-960936İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 8,8İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-960836İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 8,8İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-961236İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 8,8İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-961436İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 8,8İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2023-2476035İzleyin
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
YüksekCVSS 8,8İstismar yokEPSS %1ofcms project · ofcms15 Mar 2023
- CVE-2019-961629İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 7,2İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-961329İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 7,2İstismar yokEPSS %3ofcms project · ofcms6 Mar 2019
- CVE-2019-961528İzleyin
An issue was discovered in OFCMS before 1.1.3.
YüksekCVSS 7,2İstismar yokEPSS %1ofcms project · ofcms6 Mar 2019
- CVE-2019-961126İzleyin
An issue was discovered in OFCMS before 1.1.3.
OrtaCVSS 6,5İstismar yokEPSS %1ofcms project · ofcms6 Mar 2019
- CVE-2024-4823526İzleyin
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
OrtaCVSS 6,5İstismar yokEPSS %1ofcms project · ofcms25 Eki 2024
- CVE-2024-4823626İzleyin
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of t
OrtaCVSS 6,5İstismar yokEPSS %1ofcms project · ofcms25 Eki 2024
- CVE-2022-2965324İzleyin
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
OrtaCVSS 6,1İstismar yokEPSS %1ofcms project · ofcms2 Haz 2022
- CVE-2022-2796021İzleyin
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitraril
OrtaCVSS 5,4İstismar yokEPSS %0ofcms project · ofcms10 Nis 2022
- CVE-2023-5180721İzleyin
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the tit
OrtaCVSS 5,4İstismar yokEPSS %0ofcms project · ofcms16 Oca 2024
- CVE-2022-2796121İzleyin
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML
OrtaCVSS 5,4İstismar yokEPSS %0ofcms project · ofcms10 Nis 2022
- CVE-2024-941121İzleyin
OFCMS add.json add cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0ofcms project · ofcms1 Eki 2024
- CVE-2025-155721İzleyin
OFCMS cross-site request forgery
OrtaCVSS 5,3İstismar yokEPSS %0ofcms project · ofcms22 Şub 2025
- CVE-2019-961017İzleyin
An issue was discovered in OFCMS before 1.1.3.
OrtaCVSS 4,3İstismar yokEPSS %1ofcms project · ofcms6 Mar 2019