Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
naviwebs navigate cms - vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2020-14014
An issue exists in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.
Naviwebs Navigate Cms 2.8
Naviwebs Navigate Cms 2.9
6.1
CVSSv3
CVE-2020-13796
An issue exists in Navigate CMS up to and including 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.
Naviwebs Navigate Cms
6.1
CVSSv3
CVE-2020-13797
An issue exists in Navigate CMS up to and including 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.
Naviwebs Navigate Cms
5.3
CVSSv3
CVE-2020-13795
An issue exists in Navigate CMS up to and including 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
Naviwebs Navigate Cms
6.1
CVSSv3
CVE-2020-13798
An issue exists in Navigate CMS up to and including 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.
Naviwebs Navigate Cms
5.4
CVSSv3
CVE-2018-18029
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
Naviwebs Navigate Cms -
7.5
CVSSv3
CVE-2020-14015
An issue exists in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue settin...
Naviwebs Navigate Cms 2.9
5.3
CVSSv3
CVE-2020-14016
An issue exists in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_found message when the provided username or email add...
Naviwebs Navigate Cms 2.9
7.5
CVSSv3
CVE-2020-14017
An issue exists in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing sessions, or view...
Naviwebs Navigate Cms 2.9
6.1
CVSSv3
CVE-2020-14018
An issue exists in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users, and on the page to edit users. This is present in both the User field and the E-Mail field. On the Edit user page, the XSS is only triggered via the E-Mail f...
Naviwebs Navigate Cms 2.9
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »