Spotweb

Spotweb Project · 10 CVEs

CVE-2021-43725
MEDIUM

There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remo…

Mar 28, 2022

CVE-2021-33966
MEDIUM

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via…

Jan 21, 2022

CVE-2021-40973
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-40972
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-40971
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-40970
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-40969
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-40968
MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remot…

Oct 1, 2021

CVE-2021-3286
CRITICAL

SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variat…

Jan 24, 2021

CVE-2020-35545
CRITICAL

Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

Dec 17, 2020

Showing 1 to 10 of 10 CVEs