SocialEngine kayıtları
socialengine üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-41460İstismar yok | SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberallsocialengine · socialengine · CWE-89 | Kritik9,3 | — | %1,0 | 23 Nis 2026 |
30İzleyin | CVE-2008-6121İstismar yok | CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP socialengine · socialengine · CWE-20 | Yüksek7,5 | — | %1,3 | 11 Şub 2009 |
30İzleyin | CVE-2008-6120İstismar yok | SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL cosocialengine · socialengine · CWE-89 | Yüksek7,5 | — | %1,1 | 11 Şub 2009 |
27İzleyin | CVE-2013-4898Kavram kanıtı | Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authensocialengine · socialengine | Orta6,5 | — | %3,1 | 29 Oca 2014 |
27İzleyin | CVE-2009-0400Kavram kanıtı | SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the categorsocialengine · socialengine · CWE-89 | Orta6,8 | — | %1,1 | 3 Şub 2009 |
25İzleyin | CVE-2026-41461İstismar yok | SocialEngine <= 7.8.0 Blind SSRF via /core/link/previewsocialengine · socialengine · CWE-918 | Orta6,3 | — | %0,5 | 23 Nis 2026 |
25İzleyin | CVE-2012-6721İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4socialengine · socialengine · CWE-352 | Orta6,3 | — | %0,3 | 11 Şub 2020 |
24İzleyin | CVE-2012-6720İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTsocialengine · socialengine · CWE-79 | Orta6,1 | — | %0,8 | 11 Şub 2020 |
- CVE-2026-4146037İzleyin
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
KritikCVSS 9,3İstismar yokEPSS %1socialengine · socialengine23 Nis 2026
- CVE-2008-612130İzleyin
CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP
YüksekCVSS 7,5İstismar yokEPSS %1socialengine · socialengine11 Şub 2009
- CVE-2008-612030İzleyin
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5İstismar yokEPSS %1socialengine · socialengine11 Şub 2009
- CVE-2013-489827İzleyin
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authen
OrtaCVSS 6,5Kavram kanıtıEPSS %3socialengine · socialengine29 Oca 2014
- CVE-2009-040027İzleyin
SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the categor
OrtaCVSS 6,8Kavram kanıtıEPSS %1socialengine · socialengine3 Şub 2009
- CVE-2026-4146125İzleyin
SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview
OrtaCVSS 6,3İstismar yokEPSS %0socialengine · socialengine23 Nis 2026
- CVE-2012-672125İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4
OrtaCVSS 6,3İstismar yokEPSS %0socialengine · socialengine11 Şub 2020
- CVE-2012-672024İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HT
OrtaCVSS 6,1İstismar yokEPSS %1socialengine · socialengine11 Şub 2020