Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magnolia Cms MEDIUM 6.1
CVE-2022-33098EPSS 52%

Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows at…

No fix yet
Fix from $1,600 2022-07-07
Magnolia Cms CRITICAL 9.8
CVE-2021-46361

An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a c…

Fix: 6.2.12+
Fix from $2,300 2022-02-11
Magnolia Cms CRITICAL 9.8
CVE-2021-46362

A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers …

Fix: 6.2.4+
Fix from $2,300 2022-02-11
Magnolia Cms HIGH 8.8
CVE-2021-46366

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Fo…

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Magnolia Cms HIGH 7.8
CVE-2021-46363

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These f…

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Magnolia Cms HIGH 7.8
CVE-2021-46364

A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Magnolia Cms HIGH 7.8
CVE-2021-46365

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Magnolia Cms MEDIUM 6.1
CVE-2021-25894

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUser…

Fix: 6.1.7 / 6.2.4+
Fix from $1,600 2021-04-02
Magnolia Cms MEDIUM 5.4
CVE-2021-25893

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

Fix: 6.1.7 / 6.2.4+
Fix from $1,600 2021-04-02