ZeroHour

Vulnerabilities

31 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-58134
+1 in the same advisory: …58135
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default.

Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

NVD description · AI analysis pending
8.1
group max
<1% PoC
  • mojolicious mojolicious
CVE-2025-28367
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action.

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.

NVD description · AI analysis pending
6.52% PoC
  • mojoportal mojoportal
CVE-2024-9942
+1 in the same advisory: …9941
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
9.8
group max
1%
  • mojoomla wordpress gym management system
CVE-2021-47208
The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

NVD description · AI analysis pending
4.3<1% PoC
  • mojolicious mojolicious
CVE-2023-52178
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This is

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7.

NVD description · AI analysis pending
5.4<1%
  • mojofywp wp affiliate disclosure
CVE-2023-45292
When using the default implementation of Verify to check a Captcha, verification can be bypassed.

When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.

NVD description · AI analysis pending
5.3<1% PoC
  • mojotv base64captcha
CVE-2023-44009
+3 in the same advisory: …44011 …44008 …44012
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • mojoportal mojoportal
CVE-2023-32639
Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE).

Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

NVD description · AI analysis pending
5.5<1%
  • moj applicant programme
CVE-2023-34625
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass.

ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.

NVD description · AI analysis pending
8.1<1% PoC ×2
  • showmojo mojobox firmware
CVE-2023-24323
+4 in the same advisory: …24322 …24687 …24688 …24689
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.

Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.

NVD description · AI analysis pending
8.8
group max
1% PoC
  • mojoportal mojoportal
CVE-2023-23086
+1 in the same advisory: …23087
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.

Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.

NVD description · AI analysis pending
9.8<1% PoC
  • mojojson project mojojson
CVE-2022-40123
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx.

mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.

NVD description · AI analysis pending
6.51% PoC
  • mojoportal mojoportal
CVE-2022-40341
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.

mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.

NVD description · AI analysis pending
8.81% PoC
  • mojoportal mojoportal
CVE-2021-43785
@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component.

@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code.

NVD description · AI analysis pending
6.11%
  • emoji button project emoji button
CVE-2020-7626
karma-mojo through 1.0.1 is vulnerable to Command Injection.

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

NVD description · AI analysis pending
9.84% PoC
  • karma-mojo project karma-mojo
CVE-2019-20343
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can sp

The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).

NVD description · AI analysis pending
9.82%
  • mojohaus exec maven
CVE-2018-7447
mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input.

mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts

NVD description · AI analysis pending
4.8<1%
  • mojoportal mojoportal
CVE-2017-1000457
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpk

Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.

NVD description · AI analysis pending
4.8<1%
  • mojoportal mojoportal
CVE-2017-10831
Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and ea

Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • moj.go commercial registration electronic authentication software
CVE-2017-2233
Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain

Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • moj pdf digital signature
CVE-2017-2232
Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an un

Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • moj shinseiyo sogo soft