seeddms kayıtları
seeddms üreticisine ait 33 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-20 Improper Input Validation2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
33 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-44938İstismar yok | Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.seeddms · seeddms · CWE-330 | Kritik9,8 | — | %1,0 | 8 Ara 2022 |
36İzleyin | CVE-2018-12941İstismar yok | This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a systemseeddms · seeddms · CWE-20 | Yüksek8,8 | — | %3,6 | 31 Tem 2018 |
36İzleyin | CVE-2018-12940İstismar yok | Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackseeddms · seeddms · CWE-434 | Yüksek8,8 | — | %2,5 | 31 Tem 2018 |
35İzleyin | CVE-2018-12942İstismar yok | SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticateseeddms · seeddms · CWE-89 | Yüksek8,8 | — | %1,5 | 31 Tem 2018 |
35İzleyin | CVE-2021-33223İstismar yok | An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php filseeddms · seeddms · CWE-639 | Yüksek8,8 | — | %0,8 | 6 Haz 2023 |
34İzleyin | CVE-2019-12744Kavram kanıtı | SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability thaseeddms · seeddms · CWE-434 | Yüksek7,5 | — | %11,7 | 20 Haz 2019 |
28İzleyin | CVE-2025-45752İstismar yok | A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functiseeddms · seeddms · CWE-94 | Yüksek7,2 | — | %0,6 | 21 May 2025 |
27İzleyin | CVE-2014-2279İstismar yok | Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with seeddms · seeddms · CWE-22 | Orta6,4 | — | %5,2 | 17 Eki 2014 |
27İzleyin | CVE-2018-12939İstismar yok | A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentiallyseeddms · seeddms · CWE-22 | Orta6,5 | — | %2,0 | 31 Tem 2018 |
26İzleyin | CVE-2022-28478İstismar yok | SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal.seeddms · seeddms · CWE-22 | Orta6,5 | — | %1,5 | 6 Haz 2022 |
25İzleyin | CVE-2019-12801Kavram kanıtı | out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.seeddms · seeddms · CWE-79 | Orta6,1 | — | %1,9 | 17 Haz 2019 |
24İzleyin | CVE-2018-12943İstismar yok | Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) befoseeddms · seeddms · CWE-79 | Orta6,1 | — | %1,1 | 31 Tem 2018 |
24İzleyin | CVE-2018-12944İstismar yok | Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows seeddms · seeddms · CWE-79 | Orta6,1 | — | %1,1 | 31 Tem 2018 |
24İzleyin | CVE-2019-12932İstismar yok | A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in thseeddms · seeddms · CWE-79 | Orta6,1 | — | %0,8 | 28 Haz 2019 |
24İzleyin | CVE-2020-23048İstismar yok | SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via thseeddms · seeddms · CWE-79 | Orta6,1 | — | %0,7 | 22 Eki 2021 |
24İzleyin | CVE-2020-28727İstismar yok | Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.seeddms · seeddms · CWE-79 | Orta6,1 | — | %0,7 | 7 Ara 2020 |
24İzleyin | CVE-2020-28726İstismar yok | Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.seeddms · seeddms · CWE-601 | Orta6,1 | — | %0,6 | 24 Kas 2020 |
24İzleyin | CVE-2021-45408İstismar yok | Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sitseeddms · seeddms · CWE-601 | Orta6,1 | — | %0,6 | 4 Şub 2022 |
24İzleyin | CVE-2021-39425İstismar yok | SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability.seeddms · seeddms · CWE-601 | Orta6,1 | — | %0,5 | 20 Tem 2023 |
24İzleyin | CVE-2021-39421İstismar yok | A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payloaseeddms · seeddms · CWE-79 | Orta6,1 | — | %0,4 | 24 Tem 2023 |
22İzleyin | CVE-2019-12745Kavram kanıtı | out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.seeddms · seeddms · CWE-79 | Orta5,4 | — | %2,6 | 20 Haz 2019 |
21İzleyin | CVE-2014-2278İstismar yok | Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers toseeddms · seeddms · CWE-20 | Orta5,1 | — | %3,9 | 17 Eki 2014 |
21İzleyin | CVE-2022-28051İstismar yok | The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which alloseeddms · seeddms · CWE-79 | Orta5,4 | — | %0,8 | 6 Haz 2022 |
21İzleyin | CVE-2025-25461Kavram kanıtı | A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29.seeddms · seeddms · CWE-79 | Orta5,4 | — | %0,5 | 28 Şub 2025 |
21İzleyin | CVE-2024-46409İstismar yok | A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injectingseeddms · seeddms · CWE-79 | Orta5,4 | — | %0,3 | 4 Eki 2024 |
- CVE-2022-4493839İzleyin
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
KritikCVSS 9,8İstismar yokEPSS %1seeddms · seeddms8 Ara 2022
- CVE-2018-1294136İzleyin
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system
YüksekCVSS 8,8İstismar yokEPSS %4seeddms · seeddms31 Tem 2018
- CVE-2018-1294036İzleyin
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attack
YüksekCVSS 8,8İstismar yokEPSS %3seeddms · seeddms31 Tem 2018
- CVE-2018-1294235İzleyin
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticate
YüksekCVSS 8,8İstismar yokEPSS %2seeddms · seeddms31 Tem 2018
- CVE-2021-3322335İzleyin
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php fil
YüksekCVSS 8,8İstismar yokEPSS %1seeddms · seeddms6 Haz 2023
- CVE-2019-1274434İzleyin
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability tha
YüksekCVSS 7,5Kavram kanıtıEPSS %12seeddms · seeddms20 Haz 2019
- CVE-2025-4575228İzleyin
A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functi
YüksekCVSS 7,2İstismar yokEPSS %1seeddms · seeddms21 May 2025
- CVE-2014-227927İzleyin
Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with
OrtaCVSS 6,4İstismar yokEPSS %5seeddms · seeddms17 Eki 2014
- CVE-2018-1293927İzleyin
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially
OrtaCVSS 6,5İstismar yokEPSS %2seeddms · seeddms31 Tem 2018
- CVE-2022-2847826İzleyin
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal.
OrtaCVSS 6,5İstismar yokEPSS %2seeddms · seeddms6 Haz 2022
- CVE-2019-1280125İzleyin
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
OrtaCVSS 6,1Kavram kanıtıEPSS %2seeddms · seeddms17 Haz 2019
- CVE-2018-1294324İzleyin
Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) befo
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms31 Tem 2018
- CVE-2018-1294424İzleyin
Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms31 Tem 2018
- CVE-2019-1293224İzleyin
A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in th
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms28 Haz 2019
- CVE-2020-2304824İzleyin
SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via th
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms22 Eki 2021
- CVE-2020-2872724İzleyin
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms7 Ara 2020
- CVE-2020-2872624İzleyin
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms24 Kas 2020
- CVE-2021-4540824İzleyin
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sit
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms4 Şub 2022
- CVE-2021-3942524İzleyin
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1seeddms · seeddms20 Tem 2023
- CVE-2021-3942124İzleyin
A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa
OrtaCVSS 6,1İstismar yokEPSS %0seeddms · seeddms24 Tem 2023
- CVE-2019-1274522İzleyin
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
OrtaCVSS 5,4Kavram kanıtıEPSS %3seeddms · seeddms20 Haz 2019
- CVE-2014-227821İzleyin
Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to
OrtaCVSS 5,1İstismar yokEPSS %4seeddms · seeddms17 Eki 2014
- CVE-2022-2805121İzleyin
The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allo
OrtaCVSS 5,4İstismar yokEPSS %1seeddms · seeddms6 Haz 2022
- CVE-2025-2546121İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29.
OrtaCVSS 5,4Kavram kanıtıEPSS %1seeddms · seeddms28 Şub 2025
- CVE-2024-4640921İzleyin
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting
OrtaCVSS 5,4İstismar yokEPSS %0seeddms · seeddms4 Eki 2024