Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-19905 +1 in the same advisory: …19906 | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-17986 | rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user. rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-16727 +1 in the same advisory: …16726 | razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |