Pagekit kayıtları
pagekit üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %15,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2022-38916İstismar yok | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious filespagekit · pagekit · CWE-434 | Kritik9,8 | — | %17,9 | 20 Eyl 2022 |
39İzleyin | CVE-2021-44135İstismar yok | pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.pagekit · pagekit · CWE-89 | Kritik9,8 | — | %1,5 | 1 Nis 2022 |
39İzleyin | CVE-2025-67164İstismar yok | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arpagekit · pagekit · CWE-78 | Kritik9,9 | — | %0,5 | 17 Ara 2025 |
39İzleyin | CVE-2025-67165İstismar yok | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.pagekit · pagekit · CWE-639 | Kritik9,8 | — | %0,5 | 17 Ara 2025 |
35İzleyin | CVE-2019-19013İstismar yok | A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.pagekit · pagekit · CWE-352 | Yüksek8,8 | — | %0,8 | 22 Kas 2019 |
32İzleyin | CVE-2017-5594Kavram kanıtı | An issue was discovered in Pagekit CMS before 1.0.11.pagekit · pagekit · CWE-640 | Yüksek7,5 | — | %7,0 | 25 Oca 2017 |
31İzleyin | CVE-2023-41005İstismar yok | An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in Upagekit · pagekit · CWE-94 | Yüksek7,8 | — | %0,6 | 28 Ağu 2023 |
24İzleyin | CVE-2018-14381İstismar yok | Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.pagekit · pagekit · CWE-601 | Orta6,1 | — | %1,0 | 18 Tem 2018 |
24İzleyin | CVE-2022-36573İstismar yok | A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted papagekit · pagekit · CWE-79 | Orta6,1 | — | %0,6 | 28 Ağu 2022 |
21İzleyin | CVE-2019-16669İstismar yok | The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is epagekit · pagekit · CWE-203 | Orta5,3 | — | %1,1 | 21 Eyl 2019 |
21İzleyin | CVE-2021-32245İstismar yok | In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.pagekit · pagekit · CWE-79 | Orta5,4 | — | %0,5 | 16 Haz 2021 |
20İzleyin | CVE-2018-11564Kavram kanıtı | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.pagekit · pagekit · CWE-79 | Orta4,8 | — | %3,2 | 1 Haz 2018 |
18İzleyin | CVE-2024-45967İstismar yok | Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.pagekit · pagekit · CWE-79 | Orta4,7 | — | %0,4 | 1 Eki 2024 |
- CVE-2022-3891644Planlayın
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
KritikCVSS 9,8İstismar yokEPSS %18pagekit · pagekit20 Eyl 2022
- CVE-2021-4413539İzleyin
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
KritikCVSS 9,8İstismar yokEPSS %2pagekit · pagekit1 Nis 2022
- CVE-2025-6716439İzleyin
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute ar
KritikCVSS 9,9İstismar yokEPSS %1pagekit · pagekit17 Ara 2025
- CVE-2025-6716539İzleyin
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
KritikCVSS 9,8İstismar yokEPSS %0pagekit · pagekit17 Ara 2025
- CVE-2019-1901335İzleyin
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
YüksekCVSS 8,8İstismar yokEPSS %1pagekit · pagekit22 Kas 2019
- CVE-2017-559432İzleyin
An issue was discovered in Pagekit CMS before 1.0.11.
YüksekCVSS 7,5Kavram kanıtıEPSS %7pagekit · pagekit25 Oca 2017
- CVE-2023-4100531İzleyin
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in U
YüksekCVSS 7,8İstismar yokEPSS %1pagekit · pagekit28 Ağu 2023
- CVE-2018-1438124İzleyin
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1pagekit · pagekit18 Tem 2018
- CVE-2022-3657324İzleyin
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
OrtaCVSS 6,1İstismar yokEPSS %1pagekit · pagekit28 Ağu 2022
- CVE-2019-1666921İzleyin
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is e
OrtaCVSS 5,3İstismar yokEPSS %1pagekit · pagekit21 Eyl 2019
- CVE-2021-3224521İzleyin
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.
OrtaCVSS 5,4İstismar yokEPSS %1pagekit · pagekit16 Haz 2021
- CVE-2018-1156420İzleyin
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
OrtaCVSS 4,8Kavram kanıtıEPSS %3pagekit · pagekit1 Haz 2018
- CVE-2024-4596718İzleyin
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
OrtaCVSS 4,7İstismar yokEPSS %0pagekit · pagekit1 Eki 2024