Known Vulnerabilities for products from Hallowelt
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Hallowelt".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-42431 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary... | 5.4 - MEDIUM | 2023-10-30 | 2023-11-08 |
| CVE-2022-42001 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and ed... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-42000 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permission... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41814 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and e... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41789 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions ... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-41611 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject ... | 4.8 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3958 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and ... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3895 json | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbi... | 6.1 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-3893 json | Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to ... | 4.8 - MEDIUM | 2022-11-15 | 2022-11-16 |
| CVE-2022-2511 json | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arb... | 6.1 - MEDIUM | 2022-07-22 | 2022-07-27 |
| CVE-2022-2510 json | Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to injec... | 6.1 - MEDIUM | 2022-07-22 | 2022-07-28 |