Known Vulnerabilities for products from Weaselcms Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Weaselcms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-17361 json | Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_I... | 6.1 - MEDIUM | 2018-09-23 | 2018-11-09 |
| CVE-2018-16352 json | There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png f... | 9.8 - CRITICAL | 2018-09-02 | 2018-10-29 |
| CVE-2018-14959 json | An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. | 8.8 - HIGH | 2018-08-05 | 2018-10-04 |
| CVE-2018-14958 json | An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description)... | 8.8 - HIGH | 2018-08-05 | 2018-10-04 |
| CVE-2018-14877 json | An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on... | 5.4 - MEDIUM | 2018-08-03 | 2018-09-27 |
Known software with vulnerabilities from Weaselcms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Weaselcms Project | Weaselcms | 0.1 |