Creatiwity / Witycms
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-29725 | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file. | HIGH | 8.8 | May 31, 2022 |
| CVE-2018-16250 | The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name"… | MEDIUM | 5.4 | Jun 20, 2019 |
| CVE-2018-16251 | A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin… | MEDIUM | 4.3 | Jun 20, 2019 |
| CVE-2018-16776 | wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. | MEDIUM | 4.8 | Sep 10, 2018 |
| CVE-2018-14029 | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's em… | HIGH | 8.8 | Jul 13, 2018 |
| CVE-2018-12065 | A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP c… | CRITICAL | 9.8 | Jun 8, 2018 |
| CVE-2018-11512 | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1… | MEDIUM | 4.8 | May 28, 2018 |
Showing 1 to 7 of 7 CVEs