Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Navigate_cms
(Naviwebs)Repositories | https://github.com/NavigateCMS/Navigate-CMS |
#Vulnerabilities | 20 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-06-28 | CVE-2020-23711 | SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. | Navigate_cms | 9.8 | ||
2021-08-06 | CVE-2021-36454 | Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15)... | Navigate_cms | 5.4 | ||
2021-08-06 | CVE-2021-36455 | SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php. | Navigate_cms | 8.8 | ||
2022-01-06 | CVE-2021-44351 | An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter. | Navigate_cms | 7.5 | ||
2022-01-19 | CVE-2021-44299 | A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload. | Navigate_cms | 5.4 | ||
2022-04-28 | CVE-2022-28117 | A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter. | Navigate_cms | 4.9 | ||
2018-10-09 | CVE-2018-18029 | Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. | Navigate_cms | 5.4 | ||
2018-10-04 | CVE-2018-17849 | Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload. | Navigate_cms | 5.4 | ||
2018-10-03 | CVE-2018-17553 | An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php. | Navigate_cms | 8.8 | ||
2018-10-03 | CVE-2018-17552 | SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie. | Navigate_cms | 9.8 |