torchbox kayıtları
torchbox üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-280 Improper Handling of Insufficient Permissions or Privileges8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-400 Uncontrolled Resource Consumption2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-208 Observable Timing Discrepancy1
- CWE-1333 Inefficient Regular Expression Complexity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
29İzleyin | CVE-2026-54263İstismar yok | Wagtail: Reflected XSS in dynamic image URL generator viewtorchbox · wagtail · CWE-79 | Yüksek7,3 | — | %0,4 | 1 Tem 2026 |
27İzleyin | CVE-2020-11001İstismar yok | Possible XSS attack in Wagtailtorchbox · wagtail · CWE-79 | Orta6,8 | — | %1,3 | 14 Nis 2020 |
26İzleyin | CVE-2026-44197İstismar yok | Wagtail: Improper permission handling when comparing revisionstorchbox · wagtail · CWE-280 | Orta6,5 | — | %0,3 | 11 May 2026 |
26İzleyin | CVE-2026-54261İstismar yok | Wagtail: Improper permission handling in image previewtorchbox · wagtail · CWE-280 | Orta6,5 | — | %0,3 | 1 Tem 2026 |
26İzleyin | CVE-2026-44200İstismar yok | Wagtail: Improper permission handling when copying pagestorchbox · wagtail · CWE-280 | Orta6,5 | — | %0,3 | 11 May 2026 |
26İzleyin | CVE-2026-44199İstismar yok | Wagtail: Improper permission handling when deleting form submissionstorchbox · wagtail · CWE-280 | Orta6,5 | — | %0,3 | 11 May 2026 |
24İzleyin | CVE-2026-28222İstismar yok | Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributestorchbox · wagtail · CWE-79 | Orta6,1 | — | %0,6 | 5 Mar 2026 |
24İzleyin | CVE-2026-28223İstismar yok | Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interfacetorchbox · wagtail · CWE-79 | Orta6,1 | — | %0,6 | 5 Mar 2026 |
21İzleyin | CVE-2021-32681İstismar yok | Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blockstorchbox · wagtail · CWE-79 | Orta5,4 | — | %1,1 | 17 Haz 2021 |
21İzleyin | CVE-2020-15118İstismar yok | Cross-Site Scripting in Wagtailtorchbox · wagtail · CWE-79 | Orta5,4 | — | %1,1 | 20 Tem 2020 |
21İzleyin | CVE-2023-28836İstismar yok | Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin viewstorchbox · wagtail · CWE-79 | Orta5,4 | — | %0,8 | 3 Nis 2023 |
21İzleyin | CVE-2026-44201İstismar yok | Wagtail: Improper restriction handling on Documents and Images APItorchbox · wagtail · CWE-280 | Orta5,3 | — | %0,3 | 11 May 2026 |
20İzleyin | CVE-2026-25517İstismar yok | Wagtail has improper permission handling on admin preview endpointstorchbox · wagtail · CWE-862 | Orta5,1 | — | %0,4 | 4 Şub 2026 |
19İzleyin | CVE-2023-28837İstismar yok | Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large filestorchbox · wagtail · CWE-400 | Orta4,9 | — | %1,1 | 3 Nis 2023 |
19İzleyin | CVE-2021-29434İstismar yok | Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fieldstorchbox · wagtail · CWE-79 | Orta4,8 | — | %0,6 | 19 Nis 2021 |
19İzleyin | CVE-2024-39317İstismar yok | Wagtail regular expression denial-of-service via search query parsingtorchbox · wagtail · CWE-1333 | Orta4,9 | — | %0,6 | 11 Tem 2024 |
18İzleyin | CVE-2020-11037İstismar yok | Potential Observable Timing Discrepancy in Wagtailtorchbox · wagtail · CWE-208 | Orta4,7 | — | %0,3 | 30 Nis 2020 |
17İzleyin | CVE-2022-21683İstismar yok | Comment reply notifications sent to incorrect users in wagtailtorchbox · wagtail · CWE-200 | Orta4,3 | — | %1,0 | 18 Oca 2022 |
17İzleyin | CVE-2026-54259İstismar yok | Wagtail: Improper restriction handling on Documents and Images chosen endpointstorchbox · wagtail · CWE-280 | Orta4,3 | — | %0,3 | 1 Tem 2026 |
17İzleyin | CVE-2026-44198İstismar yok | Wagtail: Improper permission handling when viewing page historytorchbox · wagtail · CWE-280 | Orta4,3 | — | %0,3 | 11 May 2026 |
17İzleyin | CVE-2026-54262İstismar yok | Wagtail: Pages translations can be created without page permissions when using simple_translationtorchbox · wagtail · CWE-280 | Orta4,3 | — | %0,3 | 1 Tem 2026 |
10İzleyin | CVE-2023-45809İstismar yok | Disclosure of user names via admin bulk action views in wagtailtorchbox · wagtail · CWE-200 | Düşük2,7 | — | %0,5 | 19 Eki 2023 |
10İzleyin | CVE-2026-54260İstismar yok | Wagtail: Denial of service via unbounded filter specs in the image previewtorchbox · wagtail · CWE-400 | Düşük2,7 | — | %0,4 | 1 Tem 2026 |
- CVE-2026-5426329İzleyin
Wagtail: Reflected XSS in dynamic image URL generator view
YüksekCVSS 7,3İstismar yokEPSS %0torchbox · wagtail1 Tem 2026
- CVE-2020-1100127İzleyin
Possible XSS attack in Wagtail
OrtaCVSS 6,8İstismar yokEPSS %1torchbox · wagtail14 Nis 2020
- CVE-2026-4419726İzleyin
Wagtail: Improper permission handling when comparing revisions
OrtaCVSS 6,5İstismar yokEPSS %0torchbox · wagtail11 May 2026
- CVE-2026-5426126İzleyin
Wagtail: Improper permission handling in image preview
OrtaCVSS 6,5İstismar yokEPSS %0torchbox · wagtail1 Tem 2026
- CVE-2026-4420026İzleyin
Wagtail: Improper permission handling when copying pages
OrtaCVSS 6,5İstismar yokEPSS %0torchbox · wagtail11 May 2026
- CVE-2026-4419926İzleyin
Wagtail: Improper permission handling when deleting form submissions
OrtaCVSS 6,5İstismar yokEPSS %0torchbox · wagtail11 May 2026
- CVE-2026-2822224İzleyin
Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes
OrtaCVSS 6,1İstismar yokEPSS %1torchbox · wagtail5 Mar 2026
- CVE-2026-2822324İzleyin
Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface
OrtaCVSS 6,1İstismar yokEPSS %1torchbox · wagtail5 Mar 2026
- CVE-2021-3268121İzleyin
Improper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blocks
OrtaCVSS 5,4İstismar yokEPSS %1torchbox · wagtail17 Haz 2021
- CVE-2020-1511821İzleyin
Cross-Site Scripting in Wagtail
OrtaCVSS 5,4İstismar yokEPSS %1torchbox · wagtail20 Tem 2020
- CVE-2023-2883621İzleyin
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
OrtaCVSS 5,4İstismar yokEPSS %1torchbox · wagtail3 Nis 2023
- CVE-2026-4420121İzleyin
Wagtail: Improper restriction handling on Documents and Images API
OrtaCVSS 5,3İstismar yokEPSS %0torchbox · wagtail11 May 2026
- CVE-2026-2551720İzleyin
Wagtail has improper permission handling on admin preview endpoints
OrtaCVSS 5,1İstismar yokEPSS %0torchbox · wagtail4 Şub 2026
- CVE-2023-2883719İzleyin
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
OrtaCVSS 4,9İstismar yokEPSS %1torchbox · wagtail3 Nis 2023
- CVE-2021-2943419İzleyin
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
OrtaCVSS 4,8İstismar yokEPSS %1torchbox · wagtail19 Nis 2021
- CVE-2024-3931719İzleyin
Wagtail regular expression denial-of-service via search query parsing
OrtaCVSS 4,9İstismar yokEPSS %1torchbox · wagtail11 Tem 2024
- CVE-2020-1103718İzleyin
Potential Observable Timing Discrepancy in Wagtail
OrtaCVSS 4,7İstismar yokEPSS %0torchbox · wagtail30 Nis 2020
- CVE-2022-2168317İzleyin
Comment reply notifications sent to incorrect users in wagtail
OrtaCVSS 4,3İstismar yokEPSS %1torchbox · wagtail18 Oca 2022
- CVE-2026-5425917İzleyin
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
OrtaCVSS 4,3İstismar yokEPSS %0torchbox · wagtail1 Tem 2026
- CVE-2026-4419817İzleyin
Wagtail: Improper permission handling when viewing page history
OrtaCVSS 4,3İstismar yokEPSS %0torchbox · wagtail11 May 2026
- CVE-2026-5426217İzleyin
Wagtail: Pages translations can be created without page permissions when using simple_translation
OrtaCVSS 4,3İstismar yokEPSS %0torchbox · wagtail1 Tem 2026
- CVE-2023-4580910İzleyin
Disclosure of user names via admin bulk action views in wagtail
DüşükCVSS 2,7İstismar yokEPSS %0torchbox · wagtail19 Eki 2023
- CVE-2026-5426010İzleyin
Wagtail: Denial of service via unbounded filter specs in the image preview
DüşükCVSS 2,7İstismar yokEPSS %0torchbox · wagtail1 Tem 2026