CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2021-29054 HIGH

Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS Light through 21.02 and Papoo CMS Pro…

CVSS 8.8 EPSS 0.78% Apr 13, 2021
CVE-2014-9522 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 EPSS 3.50% Jan 5, 2015
CVE-2009-0735 MEDIUM

Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows…

CVSS 5.1 EPSS 2.15% Feb 25, 2009
CVE-2008-3724 HIGH

SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl parameter.

CVSS 7.5 EPSS 1.26% Aug 20, 2008
CVE-2007-3494 MEDIUM

Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users…

CVSS 6.8 EPSS 2.05% Jun 29, 2007
CVE-2007-3453 HIGH

SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid parameter to certai…

CVSS 7.5 EPSS 1.26% Jun 27, 2007
CVE-2007-3269 LOW

Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) th…

CVSS 3.5 EPSS 1.81% Jun 19, 2007
CVE-2007-2320 HIGH

SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a diff…

CVSS 7.5 EPSS 1.20% Apr 26, 2007
CVE-2006-3572 HIGH

SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

CVSS 7.5 EPSS 2.01% Jul 13, 2006
CVE-2006-3571 LOW

Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrary web script or HT…

CVSS 2.6 EPSS 2.44% Jul 13, 2006
CVE-2006-1918 LOW

Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1…

CVSS 2.6 EPSS 1.71% Apr 20, 2006
CVE-2006-1766 MEDIUM

Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang an…

CVSS 6.4 EPSS 1.01% Apr 13, 2006
CVE-2006-0569 MEDIUM

Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the us…

CVSS 4.3 EPSS 1.18% Feb 7, 2006
CVE-2005-4478 HIGH

Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a)…

CVSS 7.5 EPSS 1.30% Dec 22, 2005

Showing 1 to 14 CVEs · page 1