Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2020-37054
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML pa…
Navigate Cms
No fix yet
MEDIUM 6.5
CVE-2020-37053
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx…
Navigate Cms
No fix yet
MEDIUM 5.4
CVE-2021-44299
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to exec…
Navigate Cms
Patch available
HIGH 7.5
CVE-2021-44351
An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.
Navigate Cms
No fix yet
HIGH 8.8
CVE-2021-36455
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
Navigate Cms
No fix yet
MEDIUM 5.4
CVE-2021-36454
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.…
Navigate Cms
Patch available
CRITICAL 9.8
CVE-2021-37473
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request…
Navigatecms
after 2.9.4
CRITICAL 9.8
CVE-2021-37475
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which re…
Navigatecms
after 2.9.4
CRITICAL 9.8
CVE-2021-37476
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which resu…
Navigatecms
after 2.9.4
CRITICAL 9.8
CVE-2021-37477
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in ar…
Navigatecms
after 2.9.4
CRITICAL 9.8
CVE-2021-37478
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql qu…
Navigatecms
after 2.9.4
CRITICAL 9.8
CVE-2020-23711
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
Navigate Cms
Patch available
MEDIUM 5.4
CVE-2020-23654
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
Navigatecms
No fix yet
MEDIUM 5.4
CVE-2020-23655
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
Navigatecms
No fix yet
MEDIUM 5.4
CVE-2020-23656
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
Navigatecms
No fix yet
MEDIUM 5.4
CVE-2020-23657
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
Navigatecms
No fix yet
HIGH 7.5
CVE-2020-14017
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in …
Navigate Cms
No fix yet
MEDIUM 6.1
CVE-2020-14018
An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users, and on the page to…
Navigate Cms
No fix yet
MEDIUM 5.3
CVE-2020-14016
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username o…
Navigate Cms
No fix yet
HIGH 7.5
CVE-2020-14015
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset t…
Navigate Cms
No fix yet
MEDIUM 5.4
CVE-2020-14014
An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data vali…
Navigate Cms
No fix yet
CRITICAL 9.8
CVE-2020-14067
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may con…
Navigatecms
Patch available
MEDIUM 6.1
CVE-2020-13796
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.
Navigate Cms
after 2.8.7
MEDIUM 6.1
CVE-2020-13797
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.
Navigate Cms
after 2.8.7
MEDIUM 6.1
CVE-2020-13798
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.
Navigate Cms
after 2.8.7
MEDIUM 5.3
CVE-2020-13795
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../…
Navigate Cms
after 2.8.7
MEDIUM 5.4
CVE-2018-18029
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
Navigate Cms
Patch available
MEDIUM 5.4
CVE-2018-17849
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.
Navigate Cms
No fix yet
HIGH 8.8
CVE-2018-17553EPSS 79%
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authen…
Navigate Cms
Patch available
CRITICAL 9.8
CVE-2018-17552EPSS 84%
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
Navigate Cms
Patch available