ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-26136
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

NVD description · AI analysis pending
9.8<1%
  • wangl1989 mysiteforme
CVE-2024-57766
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • wangl1989 mysiteforme
CVE-2024-13136
+3 in the same advisory: …13139 …13138 …13137
A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical.

A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3
group max
<1% PoC ×2
  • wangl1989 mysiteforme
CVE-2022-29309
mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

NVD description · AI analysis pending
7.5<1% PoC
  • wangl1989 mysiteforme
CVE-2021-46026
mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.

mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.

NVD description · AI analysis pending
5.4<1% PoC
  • wangl1989 mysiteforme
CVE-2021-46027
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management.

mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added

NVD description · AI analysis pending
6.5<1% PoC
  • wangl1989 mysiteforme