ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-47135
Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions.

Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions.

NVD description · AI analysis pending
8.8<1%
  • chronoengine chronoforms
CVE-2021-28377
+1 in the same advisory: …28376
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

NVD description · AI analysis pending
5.3
group max
8% PoC
  • chronoengine chronoforums
CVE-2020-27459
Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post.

Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.

NVD description · AI analysis pending
6.1<1%
  • chronoengine chronoforums