Known Vulnerabilities for Evergreen by Evergreen-ils
Listed below are 3 of the newest known vulnerabilities associated with "Evergreen" by "Evergreen-ils".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-67622 json | Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS... | Not Provided | 2025-12-24 | 2026-04-27 |
| CVE-2025-64234 json | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Expl... | Not Provided | 2025-10-29 | 2026-04-27 |
| CVE-2025-49373 json | Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster... | Not Provided | 2025-10-22 | 2026-04-27 |
| CVE-2024-29099 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poste... | Not Provided | 2024-03-19 | 2026-04-28 |
| CVE-2023-51423 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webina... | Not Provided | 2023-12-31 | 2026-04-28 |
| CVE-2023-51422 json | Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant w... | Not Provided | 2023-12-29 | 2026-04-28 |
| CVE-2023-41127 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poste... | Not Provided | 2023-11-30 | 2026-04-28 |
| CVE-2015-2204 json | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restr... | 7.5 - HIGH | 2018-02-01 | 2023-11-07 |
| CVE-2015-2203 json | Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings ... | 6.5 - MEDIUM | 2018-02-01 | 2023-11-07 |
| CVE-2013-7435 json | The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to ... | 6.5 - MEDIUM | 2018-02-01 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Evergreen-ils | Evergreen | 3.3.1 | |||
| Application | Evergreen-ils | Evergreen | 3.3.0 | |||
| Application | Evergreen-ils | Evergreen | 3.2.6 | |||
| Application | Evergreen-ils | Evergreen | 3.2.5 | |||
| Application | Evergreen-ils | Evergreen | 3.2.4 | |||
| Application | Evergreen-ils | Evergreen | 3.2.3 | |||
| Application | Evergreen-ils | Evergreen | 3.2.2 | |||
| Application | Evergreen-ils | Evergreen | 3.2 | |||
| Application | Evergreen-ils | Evergreen | 3.1.9 | |||
| Application | Evergreen-ils | Evergreen | 3.1.12 | |||
| Application | Evergreen-ils | Evergreen | 3.1.0 | |||
| Application | Evergreen-ils | Evergreen | 2.7.4 | |||
| Application | Evergreen-ils | Evergreen | 2.7.3 | |||
| Application | Evergreen-ils | Evergreen | 2.7.0 | |||
| Application | Evergreen-ils | Evergreen | 2.6.7 | |||
| Application | Evergreen-ils | Evergreen | 2.6.6 | |||
| Application | Evergreen-ils | Evergreen | 2.6.5 | |||
| Application | Evergreen-ils | Evergreen | 2.6.4 | |||
| Application | Evergreen-ils | Evergreen | 2.6.0 | |||
| Application | Evergreen-ils | Evergreen | 2.5.9 |