Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Exponent Cms CRITICAL 9.8
CVE-2016-2242EPSS 7%

Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

Patch available
Fix from $2,300 2017-01-23
Exponent Cms MEDIUM 6.1
CVE-2015-8667

Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attackers to inject arbitrary web s…

Fix: after 2.3.5
Fix from $1,600 2017-01-18
Exponent Cms MEDIUM 6.1
CVE-2015-8684

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scr…

Fix: after 2.3.5
Fix from $1,600 2017-01-18
Exponent Cms CRITICAL 9.8
CVE-2016-7790

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through…

Patch available
Fix from $2,300 2017-01-12
Exponent Cms CRITICAL 9.8
CVE-2016-7791

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to …

Patch available
Fix from $2,300 2017-01-12
Exponent Cms CRITICAL 9.8
CVE-2016-9481

In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showCo…

No fix yet
Fix from $2,300 2016-11-29
Exponent Cms CRITICAL 9.8
CVE-2016-9287

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The …

Patch available
Fix from $2,300 2016-11-15
Exponent Cms CRITICAL 9.8
CVE-2016-9288

In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropRe…

Fix: after 2.4.0
Fix from $2,300 2016-11-11
Exponent Cms MEDIUM 5.3
CVE-2016-9286

framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows …

Patch available
Fix from $1,600 2016-11-11
Exponent Cms MEDIUM 5.3
CVE-2016-9285

framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modifie…

Patch available
Fix from $1,600 2016-11-11
Exponent Cms MEDIUM 5.3
CVE-2016-9284

getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via…

Patch available
Fix from $1,600 2016-11-11
Exponent Cms HIGH 7.5
CVE-2016-9283

SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addC…

Patch available
Fix from $1,950 2016-11-11
Exponent Cms HIGH 7.5
CVE-2016-9282

SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database informatio…

Patch available
Fix from $1,950 2016-11-11
Exponent Cms CRITICAL 9.1
CVE-2016-9272

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure …

Fix: after 2.4.0
Fix from $2,300 2016-11-11
Exponent Cms HIGH 8.8
CVE-2016-9242

Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow…

Patch available
Fix from $1,950 2016-11-07
Exponent Cms HIGH 7.5
CVE-2016-9184

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in t…

Patch available
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9183

In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method …

Patch available
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9182

Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method …

Patch available
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9135

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version param…

Patch available
Fix from $1,950 2016-11-03
Exponent Cms HIGH 7.5
CVE-2016-9134

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure.

Patch available
Fix from $1,950 2016-11-03
Exponent Cms CRITICAL 9.8
CVE-2016-7453

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.

Fix: after 2.3.9
Fix from $2,300 2016-11-03
Exponent Cms HIGH 7.5
CVE-2016-7452

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directo…

Fix: after 2.3.9
Fix from $1,950 2016-11-03
Exponent Cms CRITICAL 9.8
CVE-2016-7095

Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected fold…

Fix: after 2.3.8
Fix from $2,300 2016-11-03
Exponent Cms HIGH 7.5
CVE-2013-3295

Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to include and execute arbitrary loca…

Fix: after 2.2.0
Fix from $1,950 2014-12-30
Exponent Cms HIGH 7.5
CVE-2013-3294

Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via …

Fix: after 2.2.0
Fix from $1,950 2014-02-11