Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sulu MEDIUM 5.4
CVE-2024-47618

Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload a…

Fix: 2.6.5+
Fix from $1,600 2024-10-03
Sulu MEDIUM 6.1
CVE-2024-47617

Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download UR…

Patch available
Fix from $1,600 2024-10-03
Suluformbundle MEDIUM 6.1
CVE-2024-37156

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned…

Fix: 2.5.3+
Fix from $1,600 2024-06-06
Sulu HIGH 8.1
CVE-2024-27915

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of ro…

Fix: 2.4.17 / 2.5.13+
Fix from $1,950 2024-03-06
Sulu HIGH 8.8
CVE-2021-43836

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files …

Fix: 1.6.44 / 2.2.18+
Fix from $1,950 2021-12-15
Sulu HIGH 7.2
CVE-2021-43835

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of…

Fix: 2.2.18 / 2.3.8+
Fix from $1,950 2021-12-15
Sulu MEDIUM 5.3
CVE-2020-15132

In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username …

Fix: 1.6.35 / 2.0.10+
Fix from $1,600 2020-08-05
Sulu Standard MEDIUM 5.4
CVE-2017-1000465

Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption…

Mitigation only
Fix from $1,600 2018-01-09