Onenav
Onenav · 7 CVEs
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
Mar 28, 2025
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
Mar 28, 2025
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=a…
Apr 30, 2024
OneNav API improper authentication
Jan 7, 2024
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
Mar 12, 2022
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to b…
Aug 16, 2021
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not…
Aug 5, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-28097 | OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers. | MEDIUM | 0.21% | Mar 28, 2025 |
| CVE-2025-28096 | OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. | MEDIUM | 0.23% | Mar 28, 2025 |
| CVE-2024-33832 | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info. | MEDIUM | 0.72% | Apr 30, 2024 |
| CVE-2023-7210 | OneNav API improper authentication | CRITICAL | 0.98% | Jan 7, 2024 |
| CVE-2022-26276 | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. | MEDIUM | 1.19% | Mar 12, 2022 |
| CVE-2021-38712 | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configurati… | HIGH | 1.15% | Aug 16, 2021 |
| CVE-2021-38138 | OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because t… | MEDIUM | 1.50% | Aug 5, 2021 |
Showing 1 to 7 of 7 CVEs