Apachefriends / Xampp
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-10062 | XAMPP WebDAV PHP Upload Authentication Bypass RCE | HIGH | 8.7 | Aug 30, 2025 |
| CVE-2024-5055 | Vulnerability of uncontrolled resource consumption in XAMPP | HIGH | 7.5 | May 17, 2024 |
| CVE-2024-0338 | Buffer Overflow Vulnerability in XAMPP | CRITICAL | 9.8 | Feb 2, 2024 |
| CVE-2022-47637 | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative… | MEDIUM | 6.7 | Sep 12, 2023 |
| CVE-2017-20018 | XAMPP Installer uncontrolled search path | HIGH | 7.8 | Jun 9, 2022 |
| CVE-2022-29376 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via o… | HIGH | 8.8 | May 23, 2022 |
| CVE-2020-11107 | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration i… | HIGH | 8.8 | Apr 2, 2020 |
| CVE-2019-8920 | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569. | MEDIUM | 6.1 | Jul 9, 2019 |
| CVE-2019-8924 | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. | MEDIUM | 6.1 | May 17, 2019 |
| CVE-2019-8923 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | CRITICAL | 9.8 | May 14, 2019 |
| CVE-2013-2586 | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS)… | MEDIUM | 4.3 | Sep 29, 2014 |
| CVE-2008-6499 | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variab… | MEDIUM | 5.5 | Mar 20, 2009 |
| CVE-2008-6498 | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for… | MEDIUM | 6.8 | Mar 20, 2009 |
| CVE-2009-0919 | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default passw… | HIGH | 7.5 | Mar 16, 2009 |
| CVE-2008-4450 | Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for Windows 1.6.8 allows remote attackers to inject arbitrary web script or HTML via the (1) dbs… | MEDIUM | 4.3 | Oct 6, 2008 |
| CVE-2008-3569 | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or… | MEDIUM | 4.3 | Aug 10, 2008 |
| CVE-2006-4994 | Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in… | MEDIUM | 4.6 | Sep 26, 2006 |
Showing 1 to 16 of 16 CVEs