Vulnerabilities
41 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-1034 | There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-0951 | File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2022-0962 | Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-0880 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-0409 | Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2. Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-0362 | SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-4172 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-0079 | showdoc is vulnerable to Generation of Error Message Containing Sensitive Information showdoc is vulnerable to Generation of Error Message Containing Sensitive Information NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2021-4168 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) showdoc is vulnerable to Cross-Site Request Forgery (CSRF) NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2021-4000 | showdoc is vulnerable to URL Redirection to Untrusted Site showdoc is vulnerable to URL Redirection to Untrusted Site NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-4017 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) showdoc is vulnerable to Cross-Site Request Forgery (CSRF) NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2021-3683 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) showdoc is vulnerable to Cross-Site Request Forgery (CSRF) NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2021-41745 | ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2021-36440 | Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2021-3678 +1 in the same advisory: …3680 | showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) NVD description · AI analysis pending | 5.9 group max | 1% |
| — | ||
| CVE-2018-19621 +1 in the same advisory: …19620 | server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2018-19609 | ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discove ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2018-19433 | ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-16342 | ShowDoc v1.8.0 has XSS via a new page. ShowDoc v1.8.0 has XSS via a new page. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |