Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Showdoc MEDIUM 5.4
CVE-2021-3775

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 2.9.12
Fix from $1,600 2021-11-13
Showdoc MEDIUM 5.4
CVE-2021-3776

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 2.9.12
Fix from $1,600 2021-11-13
Showdoc CRITICAL 9.8
CVE-2021-41745

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

Mitigation only
Fix from $2,300 2021-10-22
Showdoc CRITICAL 9.8
CVE-2021-36440

Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdat…

No fix yet
Fix from $2,300 2021-09-08
Showdoc MEDIUM 5.9
CVE-2021-3678

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Fix: 2.9.8+
Fix from $1,600 2021-08-04
Showdoc MEDIUM 6.5
CVE-2018-19621

server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

No fix yet
Fix from $1,600 2018-11-28
Showdoc MEDIUM 6.5
CVE-2018-19609

ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content,…

No fix yet
Fix from $1,600 2018-11-27
Showdoc MEDIUM 6.1
CVE-2018-19433

ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

No fix yet
Fix from $1,600 2018-11-22
Showdoc MEDIUM 5.4
CVE-2018-16342

ShowDoc v1.8.0 has XSS via a new page.

No fix yet
Fix from $1,600 2018-09-02