Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-28367 mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this v… Mojoportal 2.9.1.0+ Fix from $1,6002025-04-21 CRITICAL 9.8 CVE-2023-44011 An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin m… Mojoportal No fix yet Fix from $2,3002023-10-02 MEDIUM 6.1 CVE-2023-44012 Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.a… Mojoportal No fix yet Fix from $1,6002023-10-02 CRITICAL 9.8 CVE-2023-44008 File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. Mojoportal No fix yet Fix from $2,3002023-10-02 CRITICAL 9.8 CVE-2023-44009 File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. Mojoportal No fix yet Fix from $2,3002023-10-02 HIGH 8.8 CVE-2023-24323 Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. Mojoportal No fix yet Fix from $1,9502023-02-09 MEDIUM 6.1 CVE-2023-24322EPSS 32% A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary we… Mojoportal No fix yet Fix from $1,6002023-02-09 MEDIUM 5.4 CVE-2023-24687 Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerab… Mojoportal No fix yet Fix from $1,6002023-02-09 MEDIUM 5.3 CVE-2023-24688 An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. Mojoportal No fix yet Fix from $1,6002023-02-09 MEDIUM 6.5 CVE-2022-40123 mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability all… Mojoportal No fix yet Fix from $1,6002022-10-03 HIGH 8.8 CVE-2022-40341 mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG f… Mojoportal Mitigation only Fix from $1,9502022-09-30