Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pagekit CRITICAL 9.8
CVE-2025-67165

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

Mitigation only
Fix from $2,300 2025-12-17
Pagekit CRITICAL 9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2025-12-17
Pagekit HIGH 7.8
CVE-2023-41005

An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateCont…

No fix yet
Fix from $1,950 2023-08-28
Pagekit CRITICAL 9.8
CVE-2022-38916EPSS 18%

A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

No fix yet
Fix from $2,300 2022-09-20
Pagekit MEDIUM 6.1
CVE-2022-36573

A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj…

No fix yet
Fix from $1,600 2022-08-29
Pagekit CRITICAL 9.8
CVE-2021-44135

pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.

Fix: after 1.0.18
Fix from $2,300 2022-04-01
Pagekit MEDIUM 5.4
CVE-2021-32245

In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will …

No fix yet
Fix from $1,600 2021-06-16
Pagekit HIGH 8.8
CVE-2019-19013

A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.

No fix yet
Fix from $1,950 2019-11-22
Pagekit MEDIUM 5.3
CVE-2019-16669

The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, w…

No fix yet
Fix from $1,600 2019-09-21
Pagekit MEDIUM 6.1
CVE-2018-14381

Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.

Fix: 1.0.14+
Fix from $1,600 2018-07-18
Pagekit HIGH 7.5
CVE-2017-5594EPSS 7%

An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when…

Fix: after 1.0.10
Fix from $1,950 2017-01-25