ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-19905
+1 in the same advisory: …19906
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.

HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • razorcms razorcms
CVE-2018-17986
rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.

rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.

NVD description · AI analysis pending
8.8<1% PoC
  • razorcms razorcms
CVE-2018-16727
+1 in the same advisory: …16726
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.

razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.

NVD description · AI analysis pending
5.4<1% PoC
  • razorcms razorcms