Known Vulnerabilities for products from Spotweb Project
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Spotweb Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43725 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-03-28 | 2022-03-31 |
| CVE-2021-40973 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40972 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40971 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40970 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40969 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-02 |
| CVE-2021-40968 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-33966 json | Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via craft... | 5.4 - MEDIUM | 2022-01-21 | 2022-01-26 |
| CVE-2021-3286 json | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of... | 9.8 - CRITICAL | 2021-01-26 | 2021-01-30 |
| CVE-2020-35545 json | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. | 9.8 - CRITICAL | 2020-12-17 | 2020-12-21 |
Known software with vulnerabilities from Spotweb Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Spotweb Project | Spotweb | 1.0.0 |