Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ovidentia HIGH 7.5
CVE-2022-22914

An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in…

No fix yet
Fix from $1,950 2022-02-17
Ovidentia MEDIUM 5.4
CVE-2021-29343

Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracte…

Fix: after 6.7.7
Fix from $1,600 2021-03-30
Ovidentia HIGH 8.8
CVE-2019-13978

Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.

No fix yet
Fix from $1,950 2019-07-19
Ovidentia MEDIUM 5.4
CVE-2019-13977

index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir…

No fix yet
Fix from $1,600 2019-07-19
Ovidentia HIGH 8.8
CVE-2018-1000619

Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Auth…

Fix: after 8.4.3
Fix from $1,950 2018-07-09
Ovidentia MEDIUM 6.5
CVE-2008-4423

SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a con…

No fix yet
Fix from $1,600 2008-10-03
Ovidentia HIGH 7.5
CVE-2008-3918

SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a se…

Mitigation only
Fix from $1,950 2008-09-04