Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xampp CRITICAL 9.8
CVE-2024-0338

A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long …

Fix: after 8.2.4
Fix from $2,300 2024-02-02
Xampp MEDIUM 6.7
CVE-2022-47637

The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with admin…

Fix: after 8.1.12
Fix from $1,600 2023-09-12
Xampp HIGH 7.8
CVE-2017-20018

A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. T…

No fix yet
Fix from $1,950 2022-06-09
Xampp HIGH 8.8
CVE-2022-29376

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary …

Fix: after 8.1.4
Fix from $1,950 2022-05-23
Xampp HIGH 8.8
CVE-2020-11107EPSS 22%

An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe confi…

Fix: 7.2.29 / 7.3.16+
Fix from $1,950 2020-04-02
Xampp MEDIUM 6.1
CVE-2019-8920

iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.

No fix yet
Fix from $1,600 2019-07-09
Xampp MEDIUM 6.1
CVE-2019-8924EPSS 6%

XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.

Fix: after 5.6.8
Fix from $1,600 2019-05-17
Xampp CRITICAL 9.8
CVE-2019-8923

XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.

Fix: after 5.6.8
Fix from $2,300 2019-05-14
Xampp MEDIUM 6.8
CVE-2008-6498

Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2009-03-20
Xampp MEDIUM 5.5
CVE-2008-6499

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof criti…

No fix yet
Fix from $1,600 2009-03-20
Xampp HIGH 7.5
CVE-2009-0919EPSS 9%

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" def…

Patch available
Fix from $1,950 2009-03-16