Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pixie vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2011-4710
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 up to and including 1.04 allow remote malicious users to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
Lucidcrew Pixie 1.04
Lucidcrew Pixie 1.03
Getpixie Pixie 1.01a
Getpixie Pixie 1.01
Lucidcrew Pixie 1.02
1 EDB exploit
7.5
CVSSv2
CVE-2019-10766
Pixie versions 1.0.x prior to 1.0.3, and 2.0.x prior to 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
Pixie Project Pixie
7.5
CVSSv2
CVE-2017-12905
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote malicious users to disclose information or execute arbitrary code via the url parameter to Launderer.php.
Vebto Pixie - Image Editor 1.4
Vebto Pixie - Image Editor 1.7
5
CVSSv2
CVE-2011-3793
Pixie 1.04 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2014-3786
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote malicious users to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7362
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
Lucidcrew Pixie 1.04
7.5
CVSSv2
CVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
Lucidcrew Pixie 1.04
1 EDB exploit
4.3
CVSSv2
CVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7363
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
Lucidcrew Pixie 1.04
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »