Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mojoportal CRITICAL 9.8
CVE-2023-44011

An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin m…

No fix yet
Fix from $2,300 2023-10-02
Mojoportal MEDIUM 6.1
CVE-2023-44012

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.a…

No fix yet
Fix from $1,600 2023-10-02
Mojoportal CRITICAL 9.8
CVE-2023-44008

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

No fix yet
Fix from $2,300 2023-10-02
Mojoportal CRITICAL 9.8
CVE-2023-44009

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

No fix yet
Fix from $2,300 2023-10-02
Mojoportal HIGH 8.8
CVE-2023-24323

Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.

No fix yet
Fix from $1,950 2023-02-09
Mojoportal MEDIUM 6.1
CVE-2023-24322EPSS 32%

A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary we…

No fix yet
Fix from $1,600 2023-02-09
Mojoportal MEDIUM 5.4
CVE-2023-24687

Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerab…

No fix yet
Fix from $1,600 2023-02-09
Mojoportal MEDIUM 5.3
CVE-2023-24688

An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.

No fix yet
Fix from $1,600 2023-02-09
Mojoportal MEDIUM 6.5
CVE-2022-40123

mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability all…

No fix yet
Fix from $1,600 2022-10-03
Mojoportal HIGH 8.8
CVE-2022-40341

mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG f…

Mitigation only
Fix from $1,950 2022-09-30