Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2023-6923
The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite paramete…
Matomo
5.0.1+
MEDIUM 6.1
CVE-2022-33156
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
Integration
1.3.2+
CRITICAL 9.8
CVE-2020-29578
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker contain…
Piwik Fpm Alpine Docker Image
Mitigation only
MEDIUM 6.1
CVE-2013-0193
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This …
Matomo
1.10.1+
MEDIUM 6.1
CVE-2013-0194
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This …
Matomo
1.10.1+
MEDIUM 6.1
CVE-2013-0195
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This …
Matomo
1.10.1+
HIGH 7.5
CVE-2015-7816
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection at…
Matomo
after 2.14.3
HIGH 7.5
CVE-2015-7815
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary l…
Matomo
after 2.14.3
MEDIUM 5.0
CVE-2013-2633
Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sens…
Matomo
after 1.10.1
MEDIUM 6.8
CVE-2011-4941
Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vect…
Matomo
Mitigation only
MEDIUM 5.0
CVE-2011-3791
Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an erro…
Matomo
Mitigation only
MEDIUM 6.4
CVE-2011-0398
The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass inten…
Matomo
after 1.0
MEDIUM 5.0
CVE-2011-0400
Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…
Matomo
after 1.0
MEDIUM 5.0
CVE-2011-0401
Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denial of serv…
Matomo
after 1.0
MEDIUM 6.8
CVE-2010-2786
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified o…
Matomo
Mitigation only
HIGH 7.5
CVE-2009-4137EPSS 17%
The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserial…
Matomo
Mitigation only
MEDIUM 5.0
CVE-2009-1085
Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain th…
Matomo
after 0.2.32