Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Collabtive MEDIUM 5.4
CVE-2024-48706

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.ph…

No fix yet
Fix from $1,600 2024-10-22
Collabtive MEDIUM 5.4
CVE-2024-48707

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file…

No fix yet
Fix from $1,600 2024-10-22
Collabtive MEDIUM 5.4
CVE-2024-48708

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file ad…

No fix yet
Fix from $1,600 2024-10-22
Collabtive MEDIUM 5.4
CVE-2021-3298

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?…

No fix yet
Fix from $1,600 2021-01-29
Collabtive MEDIUM 6.1
CVE-2020-13655

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id par…

No fix yet
Fix from $1,600 2020-08-31
Collabtive CRITICAL 9.8
CVE-2013-5027

Collabtive 1.0 has incorrect access control

No fix yet
Fix from $2,300 2019-12-27
Collabtive MEDIUM 5.4
CVE-2019-8935

Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

No fix yet
Fix from $1,600 2019-02-19
Collabtive MEDIUM 6.5
CVE-2014-3246

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a filev…

No fix yet
Fix from $1,600 2014-05-13
Collabtive MEDIUM 6.8
CVE-2010-5285

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrato…

No fix yet
Fix from $1,600 2012-11-26
Collabtive HIGH 7.5
CVE-2010-4269

SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID…

No fix yet
Fix from $1,950 2010-11-17