Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2025-27910 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attacker… Tianti No fix yet Fix from $1,9502025-03-10 MEDIUM 5.4 CVE-2025-25908 A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted pa… Tianti No fix yet Fix from $1,6002025-03-10 HIGH 8.8 CVE-2025-25907 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to e… Tianti No fix yet Fix from $1,9502025-03-10 HIGH 8.8 CVE-2018-19109 tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to r… Tianti No fix yet Fix from $1,9502018-11-08 MEDIUM 6.5 CVE-2018-19110 The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admi… Tianti No fix yet Fix from $1,6002018-11-08 MEDIUM 5.4 CVE-2018-19089 tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module… Tianti No fix yet Fix from $1,6002018-11-07 MEDIUM 5.4 CVE-2018-19090 tianti 2.3 has stored XSS in the article management module via an article title. Tianti No fix yet Fix from $1,6002018-11-07 MEDIUM 5.4 CVE-2018-19091 tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. Tianti No fix yet Fix from $1,6002018-11-07