Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I\, Librarian HIGH 8.6
CVE-2024-40500

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search f…

Fix: after 5.11.0
Fix from $1,950 2024-08-12
I\, Librarian MEDIUM 5.4
CVE-2023-3021

Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

Fix: 5.10.4+
Fix from $1,600 2023-05-31
I\, Librarian MEDIUM 6.1
CVE-2019-11449

I, Librarian 4.10 has XSS via the notes.php notes parameter.

No fix yet
Fix from $1,600 2019-04-22
I\, Librarian MEDIUM 6.1
CVE-2019-11428

I, Librarian 4.10 has XSS via the export.php export_files parameter.

No fix yet
Fix from $1,600 2019-04-22
I\, Librarian MEDIUM 6.1
CVE-2019-11359

Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the p…

No fix yet
Fix from $1,600 2019-04-20
I\, Librarian CRITICAL 9.1
CVE-2018-1000138

I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker …

Fix: after 4.8
Fix from $2,300 2018-03-23
I\, Librarian CRITICAL 9.1
CVE-2018-1000141

I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining un…

Fix: after 4.9
Fix from $2,300 2018-03-23
I\, Librarian HIGH 8.8
CVE-2018-1000137

I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the a…

Fix: after 4.8
Fix from $1,950 2018-03-23
I\, Librarian MEDIUM 6.1
CVE-2018-1000139

I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attack…

Fix: after 4.8
Fix from $1,600 2018-03-23
I\, Librarian CRITICAL 10.0
CVE-2018-1000124

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s…

Fix: after 4.8
Fix from $2,300 2018-03-13
I\, Librarian CRITICAL 9.8
CVE-2017-1000235

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

Fix: after 4.6
Fix from $2,300 2017-11-17
I\, Librarian CRITICAL 9.8
CVE-2017-1000237

I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset…

Fix: after 4.6
Fix from $2,300 2017-11-17
I\, Librarian MEDIUM 6.1
CVE-2017-1000236

I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malici…

Fix: after 4.6
Fix from $1,600 2017-11-17
I\, Librarian MEDIUM 5.3
CVE-2017-1000234

I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simpl…

Fix: after 4.6
Fix from $1,600 2017-11-17
Labwiki MEDIUM 6.1
CVE-2011-4333

Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the …

Fix: after 1.1
Fix from $1,600 2017-10-23