Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-19905 HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. Razorcms No fix yet Fix from $1,6002018-12-31 MEDIUM 5.4 CVE-2018-19906 Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. Razorcms No fix yet Fix from $1,6002018-12-31 HIGH 8.8 CVE-2018-17986 rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user. Razorcms No fix yet Fix from $1,9502018-10-05 MEDIUM 5.4 CVE-2018-16727 razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. Razorcms No fix yet Fix from $1,6002018-09-12 MEDIUM 5.4 CVE-2018-16726 razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. Razorcms No fix yet Fix from $1,6002018-09-12 MEDIUM 6.5 CVE-2012-6038 admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows rem… Razorcms after 1.2 Fix from $1,6002012-11-26 MEDIUM 6.8 CVE-2012-1900 Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication… Razorcms after 1.2.1 Fix from $1,6002012-10-22 HIGH 7.5 CVE-2009-1463 Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a … Razorcms after 0.3 Fix from $1,9502009-04-28 HIGH 7.2 CVE-2009-1462 The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent wit… Razorcms after 0.3 Fix from $1,9502009-04-28 MEDIUM 6.8 CVE-2009-1459 Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for req… Razorcms after 0.3 Fix from $1,6002009-04-28