Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-48706 Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.ph… Collabtive No fix yet Fix from $1,6002024-10-22 MEDIUM 5.4 CVE-2024-48707 Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file… Collabtive No fix yet Fix from $1,6002024-10-22 MEDIUM 5.4 CVE-2024-48708 Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file ad… Collabtive No fix yet Fix from $1,6002024-10-22 MEDIUM 5.4 CVE-2021-3298 Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?… Collabtive No fix yet Fix from $1,6002021-01-29 MEDIUM 6.1 CVE-2020-13655 An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id par… Collabtive No fix yet Fix from $1,6002020-08-31 CRITICAL 9.8 CVE-2013-5027 Collabtive 1.0 has incorrect access control Collabtive No fix yet Fix from $2,3002019-12-27 MEDIUM 5.4 CVE-2019-8935 Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter. Collabtive No fix yet Fix from $1,6002019-02-19 MEDIUM 6.5 CVE-2014-3246 SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a filev… Collabtive No fix yet Fix from $1,6002014-05-13 MEDIUM 6.8 CVE-2010-5285 Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrato… Collabtive No fix yet Fix from $1,6002012-11-26 HIGH 7.5 CVE-2010-4269 SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID… Collabtive No fix yet Fix from $1,9502010-11-17