Known Vulnerabilities for products from Pkp
Listed below are 7 of the newest known vulnerabilities associated with the vendor "Pkp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-5899 json | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | 8.8 - HIGH | 2023-11-01 | 2023-11-08 |
| CVE-2023-5898 json | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | 8.8 - HIGH | 2023-11-01 | 2023-11-08 |
| CVE-2023-5889 json | Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | 8.2 - HIGH | 2023-11-01 | 2023-11-09 |
| CVE-2023-4695 json | Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | 8.1 - HIGH | 2023-09-01 | 2023-09-07 |
| CVE-2012-1469 json | Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote au... | Not Provided | 2012-09-06 | 2026-04-29 |
| CVE-2012-1468 json | Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Rol... | Not Provided | 2012-09-06 | 2026-04-29 |
| CVE-2012-1467 json | Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, al... | Not Provided | 2012-09-06 | 2026-04-29 |