Vulnerabilities
31 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-58134 +1 in the same advisory: …58135 | Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session. NVD description · AI analysis pending | 8.1 group max | <1% | PoC |
| — | |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — | |
| CVE-2024-9942 +1 in the same advisory: …9941 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-47208 | The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service. The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2023-52178 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-45292 | When using the default implementation of Verify to check a Captcha, verification can be bypassed. When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2023-44009 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2023-32639 | Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-34625 | ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock. NVD description · AI analysis pending | 8.1 | <1% | PoC ×2 |
| — | |
| CVE-2023-24323 | Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2023-23086 +1 in the same advisory: …23087 | Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function. Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-40123 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2022-40341 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2021-43785 | @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2020-7626 | karma-mojo through 1.0.1 is vulnerable to Command Injection. karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2019-20343 | The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can sp The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element). NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2018-7447 | mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2017-1000457 | Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpk Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2017-10831 | Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and ea Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-2233 | Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-2232 | Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an un Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — |