Known Vulnerabilities for products from Omeka
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Omeka".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-4561 json | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4. | 4.8 - MEDIUM | 2023-08-28 | 2023-08-29 |
| CVE-2023-4560 json | Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4. | 6.5 - MEDIUM | 2023-08-28 | 2023-08-29 |
| CVE-2023-4159 json | Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3. | 8.8 - HIGH | 2023-08-04 | 2023-08-09 |
| CVE-2023-4158 json | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3. | 5.4 - MEDIUM | 2023-08-04 | 2023-08-08 |
| CVE-2023-4157 json | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repositor... | 4.8 - MEDIUM | 2023-08-04 | 2023-11-04 |
| CVE-2023-3982 json | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. | 4.8 - MEDIUM | 2023-07-27 | 2023-08-03 |
| CVE-2023-3981 json | Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2. | 4.9 - MEDIUM | 2023-07-27 | 2023-08-03 |
| CVE-2023-3980 json | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. | 4.8 - MEDIUM | 2023-07-27 | 2023-08-03 |
| CVE-2021-26799 json | Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitra... | 6.1 - MEDIUM | 2021-07-23 | 2021-07-29 |
| CVE-2018-13423 json | admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag. | 6.1 - MEDIUM | 2018-07-07 | 2018-08-27 |
| CVE-2014-5100 json | Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authent... | Not Provided | 2014-07-25 | 2026-05-06 |
Known software with vulnerabilities from Omeka
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Omeka | Omeka | 1.0 |