İçeriğe atla
Noroxi

seeddms kayıtları

seeddms üreticisine ait 33 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

33 kayıt
  • CVE-2022-44938
    39İzleyin

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

    KritikCVSS 9,8İstismar yokEPSS %1

    seeddms · seeddms8 Ara 2022

  • CVE-2018-12941
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system

    YüksekCVSS 8,8İstismar yokEPSS %4

    seeddms · seeddms31 Tem 2018

  • CVE-2018-12940
    36İzleyin

    Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attack

    YüksekCVSS 8,8İstismar yokEPSS %3

    seeddms · seeddms31 Tem 2018

  • CVE-2018-12942
    35İzleyin

    SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticate

    YüksekCVSS 8,8İstismar yokEPSS %2

    seeddms · seeddms31 Tem 2018

  • CVE-2021-33223
    35İzleyin

    An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php fil

    YüksekCVSS 8,8İstismar yokEPSS %1

    seeddms · seeddms6 Haz 2023

  • CVE-2019-12744
    34İzleyin

    SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability tha

    YüksekCVSS 7,5Kavram kanıtıEPSS %12

    seeddms · seeddms20 Haz 2019

  • CVE-2025-45752
    28İzleyin

    A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functi

    YüksekCVSS 7,2İstismar yokEPSS %1

    seeddms · seeddms21 May 2025

  • CVE-2014-2279
    27İzleyin

    Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with

    OrtaCVSS 6,4İstismar yokEPSS %5

    seeddms · seeddms17 Eki 2014

  • CVE-2018-12939
    27İzleyin

    A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially

    OrtaCVSS 6,5İstismar yokEPSS %2

    seeddms · seeddms31 Tem 2018

  • CVE-2022-28478
    26İzleyin

    SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal.

    OrtaCVSS 6,5İstismar yokEPSS %2

    seeddms · seeddms6 Haz 2022

  • CVE-2019-12801
    25İzleyin

    out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    seeddms · seeddms17 Haz 2019

  • CVE-2018-12943
    24İzleyin

    Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) befo

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms31 Tem 2018

  • CVE-2018-12944
    24İzleyin

    Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms31 Tem 2018

  • CVE-2019-12932
    24İzleyin

    A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in th

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms28 Haz 2019

  • CVE-2020-23048
    24İzleyin

    SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via th

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms22 Eki 2021

  • CVE-2020-28727
    24İzleyin

    Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms7 Ara 2020

  • CVE-2020-28726
    24İzleyin

    Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms24 Kas 2020

  • CVE-2021-45408
    24İzleyin

    Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sit

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms4 Şub 2022

  • CVE-2021-39425
    24İzleyin

    SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %1

    seeddms · seeddms20 Tem 2023

  • CVE-2021-39421
    24İzleyin

    A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa

    OrtaCVSS 6,1İstismar yokEPSS %0

    seeddms · seeddms24 Tem 2023

  • CVE-2019-12745
    22İzleyin

    out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.

    OrtaCVSS 5,4Kavram kanıtıEPSS %3

    seeddms · seeddms20 Haz 2019

  • CVE-2014-2278
    21İzleyin

    Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to

    OrtaCVSS 5,1İstismar yokEPSS %4

    seeddms · seeddms17 Eki 2014

  • CVE-2022-28051
    21İzleyin

    The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allo

    OrtaCVSS 5,4İstismar yokEPSS %1

    seeddms · seeddms6 Haz 2022

  • CVE-2025-25461
    21İzleyin

    A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29.

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    seeddms · seeddms28 Şub 2025

  • CVE-2024-46409
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting

    OrtaCVSS 5,4İstismar yokEPSS %0

    seeddms · seeddms4 Eki 2024