Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Shirasagi HIGH 7.5
CVE-2024-46898

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploite…

Fix: 1.19.1+
Fix from $1,950 2024-10-15
Shirasagi MEDIUM 5.3
CVE-2023-41889

SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a…

Fix: 1.18.0+
Fix from $1,600 2023-09-15
Shirasagi MEDIUM 6.1
CVE-2023-36492

Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on…

Fix: 1.18.0+
Fix from $1,600 2023-09-05
Shirasagi MEDIUM 5.4
CVE-2023-38569

Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the …

Fix: 1.18.0+
Fix from $1,600 2023-09-05
Shirasagi HIGH 8.8
CVE-2023-39448

Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, …

Fix: 1.18.0+
Fix from $1,950 2023-09-05
Shirasagi MEDIUM 5.4
CVE-2023-22425

Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to in…

Fix: after 1.16.2
Fix from $1,600 2023-02-24
Shirasagi MEDIUM 6.1
CVE-2022-43479

Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and c…

Fix: after 1.15.0
Fix from $1,600 2022-12-05
Shirasagi MEDIUM 5.4
CVE-2022-43499

Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privil…

Fix: 1.16.2+
Fix from $1,600 2022-12-05
Shirasagi MEDIUM 6.1
CVE-2022-29485

Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified…

Fix: 1.14.3+
Fix from $1,600 2022-06-14
Shirasagi MEDIUM 6.1
CVE-2020-5607

Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

Fix: after 1.13.1
Fix from $1,600 2020-07-10
Shirasagi MEDIUM 6.1
CVE-2019-6009

Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

Fix: after 1.7.0
Fix from $1,600 2019-09-12