Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Navigate Cms HIGH 8.8
CVE-2020-37054

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML pa…

No fix yet
Fix from $1,950 2026-01-30
Navigate Cms MEDIUM 6.5
CVE-2020-37053

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx…

No fix yet
Fix from $1,600 2026-01-30
Navigate Cms MEDIUM 5.4
CVE-2021-44299

A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to exec…

Patch available
Fix from $1,600 2022-01-19
Navigate Cms HIGH 7.5
CVE-2021-44351

An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.

No fix yet
Fix from $1,950 2022-01-06
Navigate Cms HIGH 8.8
CVE-2021-36455

SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.

No fix yet
Fix from $1,950 2021-08-06
Navigate Cms MEDIUM 5.4
CVE-2021-36454

Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.…

Patch available
Fix from $1,600 2021-08-06
Navigatecms CRITICAL 9.8
CVE-2021-37473

In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request…

Fix: after 2.9.4
Fix from $2,300 2021-07-26
Navigatecms CRITICAL 9.8
CVE-2021-37475

In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which re…

Fix: after 2.9.4
Fix from $2,300 2021-07-26
Navigatecms CRITICAL 9.8
CVE-2021-37476

In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which resu…

Fix: after 2.9.4
Fix from $2,300 2021-07-26
Navigatecms CRITICAL 9.8
CVE-2021-37477

In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in ar…

Fix: after 2.9.4
Fix from $2,300 2021-07-26
Navigatecms CRITICAL 9.8
CVE-2021-37478

In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql qu…

Fix: after 2.9.4
Fix from $2,300 2021-07-26
Navigate Cms CRITICAL 9.8
CVE-2020-23711

SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

Patch available
Fix from $2,300 2021-06-28
Navigatecms MEDIUM 5.4
CVE-2020-23654

NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."

No fix yet
Fix from $1,600 2020-08-26
Navigatecms MEDIUM 5.4
CVE-2020-23655

NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."

No fix yet
Fix from $1,600 2020-08-26
Navigatecms MEDIUM 5.4
CVE-2020-23656

NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."

No fix yet
Fix from $1,600 2020-08-26
Navigatecms MEDIUM 5.4
CVE-2020-23657

NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."

No fix yet
Fix from $1,600 2020-08-26
Navigate Cms HIGH 7.5
CVE-2020-14017

An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in …

No fix yet
Fix from $1,950 2020-06-24
Navigate Cms MEDIUM 6.1
CVE-2020-14018

An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users, and on the page to…

No fix yet
Fix from $1,600 2020-06-24
Navigate Cms MEDIUM 5.3
CVE-2020-14016

An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username o…

No fix yet
Fix from $1,600 2020-06-24
Navigate Cms HIGH 7.5
CVE-2020-14015

An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset t…

No fix yet
Fix from $1,950 2020-06-24
Navigate Cms MEDIUM 5.4
CVE-2020-14014

An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data vali…

No fix yet
Fix from $1,600 2020-06-24
Navigatecms CRITICAL 9.8
CVE-2020-14067

The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may con…

Patch available
Fix from $2,300 2020-06-15
Navigate Cms MEDIUM 6.1
CVE-2020-13796

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.

Fix: after 2.8.7
Fix from $1,600 2020-06-03
Navigate Cms MEDIUM 6.1
CVE-2020-13797

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.

Fix: after 2.8.7
Fix from $1,600 2020-06-03
Navigate Cms MEDIUM 6.1
CVE-2020-13798

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.

Fix: after 2.8.7
Fix from $1,600 2020-06-03
Navigate Cms MEDIUM 5.3
CVE-2020-13795

An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../…

Fix: after 2.8.7
Fix from $1,600 2020-06-03
Navigate Cms MEDIUM 5.4
CVE-2018-18029

Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.

Patch available
Fix from $1,600 2018-10-09
Navigate Cms MEDIUM 5.4
CVE-2018-17849

Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.

No fix yet
Fix from $1,600 2018-10-04
Navigate Cms HIGH 8.8
CVE-2018-17553EPSS 79%

An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authen…

Patch available
Fix from $1,950 2018-10-03
Navigate Cms CRITICAL 9.8
CVE-2018-17552EPSS 84%

SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.

Patch available
Fix from $2,300 2018-10-03