QiboSoft kayıtları
qibosoft üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-17613İstismar yok | qibosoft 7 allows remote code execution because do/jf.php makes eval calls.qibosoft · qibosoft · CWE-94 | Kritik9,8 | — | %2,9 | 15 Eki 2019 |
39İzleyin | CVE-2024-1225İstismar yok | QiboSoft QiboCMS X1 Pay.php rmb_pay deserializationqibosoft · qibocms x1 · CWE-502 | Kritik9,8 | — | %0,9 | 5 Şub 2024 |
37İzleyin | CVE-2020-20944İstismar yok | An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.qibosoft · qibosoft · CWE-22 | Kritik9,1 | — | %2,0 | 27 Ara 2021 |
35İzleyin | CVE-2023-27037İstismar yok | Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.phpqibosoft · qibocms · CWE-89 | Yüksek8,8 | — | %1,5 | 16 Mar 2023 |
35İzleyin | CVE-2020-20945İstismar yok | A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add admiqibosoft · qibosoft · CWE-352 | Yüksek8,8 | — | %0,6 | 27 Ara 2021 |
35İzleyin | CVE-2018-18201İstismar yok | qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.qibosoft · qibosoft · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Eki 2018 |
30İzleyin | CVE-2019-5725İstismar yok | qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URqibosoft · qibosoft · CWE-918 | Yüksek7,5 | — | %1,5 | 8 Oca 2019 |
30İzleyin | CVE-2025-22973İstismar yok | An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/applicationqibosoft · qibocms x1 · CWE-200 | Yüksek7,5 | — | %0,5 | 20 Şub 2025 |
28İzleyin | CVE-2021-27811İstismar yok | A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0.qibosoft · qibosoft · CWE-94 | Yüksek7,2 | — | %1,2 | 21 May 2021 |
27İzleyin | CVE-2011-1064İstismar yok | SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aidqibosoft · qi bo cms · CWE-89 | Orta6,8 | — | %1,0 | 22 Şub 2011 |
24İzleyin | CVE-2020-18022İstismar yok | Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive informatqibosoft · qibocms · CWE-79 | Orta6,1 | — | %1,2 | 28 Nis 2021 |
24İzleyin | CVE-2020-20808İstismar yok | Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd aqibosoft · qibosoft · CWE-79 | Orta6,1 | — | %0,7 | 2 Ağu 2023 |
21İzleyin | CVE-2020-20946İstismar yok | Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.qibosoft · qibosoft · CWE-79 | Orta5,4 | — | %0,6 | 27 Ara 2021 |
17İzleyin | CVE-2020-20943İstismar yok | A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbqibosoft · qibosoft · CWE-352 | Orta4,3 | — | %0,4 | 27 Ara 2021 |
- CVE-2019-1761340Planlayın
qibosoft 7 allows remote code execution because do/jf.php makes eval calls.
KritikCVSS 9,8İstismar yokEPSS %3qibosoft · qibosoft15 Eki 2019
- CVE-2024-122539İzleyin
QiboSoft QiboCMS X1 Pay.php rmb_pay deserialization
KritikCVSS 9,8İstismar yokEPSS %1qibosoft · qibocms x15 Şub 2024
- CVE-2020-2094437İzleyin
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
KritikCVSS 9,1İstismar yokEPSS %2qibosoft · qibosoft27 Ara 2021
- CVE-2023-2703735İzleyin
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php
YüksekCVSS 8,8İstismar yokEPSS %1qibosoft · qibocms16 Mar 2023
- CVE-2020-2094535İzleyin
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add admi
YüksekCVSS 8,8İstismar yokEPSS %1qibosoft · qibosoft27 Ara 2021
- CVE-2018-1820135İzleyin
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
YüksekCVSS 8,8İstismar yokEPSS %0qibosoft · qibosoft9 Eki 2018
- CVE-2019-572530İzleyin
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a UR
YüksekCVSS 7,5İstismar yokEPSS %1qibosoft · qibosoft8 Oca 2019
- CVE-2025-2297330İzleyin
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application
YüksekCVSS 7,5İstismar yokEPSS %0qibosoft · qibocms x120 Şub 2025
- CVE-2021-2781128İzleyin
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0.
YüksekCVSS 7,2İstismar yokEPSS %1qibosoft · qibosoft21 May 2021
- CVE-2011-106427İzleyin
SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aid
OrtaCVSS 6,8İstismar yokEPSS %1qibosoft · qi bo cms22 Şub 2011
- CVE-2020-1802224İzleyin
Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive informat
OrtaCVSS 6,1İstismar yokEPSS %1qibosoft · qibocms28 Nis 2021
- CVE-2020-2080824İzleyin
Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd a
OrtaCVSS 6,1İstismar yokEPSS %1qibosoft · qibosoft2 Ağu 2023
- CVE-2020-2094621İzleyin
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
OrtaCVSS 5,4İstismar yokEPSS %1qibosoft · qibosoft27 Ara 2021
- CVE-2020-2094317İzleyin
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arb
OrtaCVSS 4,3İstismar yokEPSS %0qibosoft · qibosoft27 Ara 2021