Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-52367 Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field. Pivotx No fix yet Fix from $1,6002025-09-22 HIGH 7.2 CVE-2017-14958 lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload… Pivotx Patch available Fix from $1,9502017-10-02 MEDIUM 6.1 CVE-2017-9332 The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smar… Pivotx Mitigation only Fix from $1,6002017-06-06 HIGH 8.8 CVE-2017-8402 PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file. Pivotx Patch available Fix from $1,9502017-05-31 HIGH 8.8 CVE-2017-7570 PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .j… Pivotx No fix yet Fix from $1,9502017-04-07 MEDIUM 6.8 CVE-2015-5458 Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter. Pivotx after 2.3.10 Fix from $1,6002015-07-08 HIGH 7.5 CVE-2015-5457 PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute… Pivotx after 2.3.10 Fix from $1,9502015-07-08 HIGH 7.5 CVE-2014-0342 Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP … Pivotx after 2.3.8 Fix from $1,9502014-04-15 HIGH 7.5 CVE-2011-1035 The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors. Pivotx after 2.2.3 Fix from $1,9502011-02-19 MEDIUM 5.0 CVE-2011-0774 PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.p… Pivotx Patch available Fix from $1,6002011-02-04 MEDIUM 5.0 CVE-2011-0775 pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image paramete… Pivotx Mitigation only Fix from $1,6002011-02-04