Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
admin vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-34021
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.29 versions.
Church Admin Project Church Admin
6.8
CVSSv2
CVE-2016-10522
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
Rails Admin Project Rails Admin
10
CVSSv2
CVE-2007-6234
index.php in FTP Admin 0.1.0 allows remote malicious users to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
Ftp Admin Ftp Admin 0.1.0
1 EDB exploit
4.3
CVSSv2
CVE-2020-36190
RailsAdmin (aka rails_admin) prior to 1.4.3 and 2.x prior to 2.0.2 allows XSS via nested forms.
Rails Admin Project Rails Admin
4.9
CVSSv2
CVE-2007-6233
Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC sh...
Ftp Admin Ftp Admin 0.1.0
1 EDB exploit
4.3
CVSSv2
CVE-2022-0833
The Church Admin WordPress plugin prior to 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated malicious users to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a pub...
Church Admin Project Church Admin
4.3
CVSSv2
CVE-2021-28290
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin prior to 2.0.0 via unencoded value passed to the data-secret-value parameter.
Identityserver4.admin Project Identityserver4.admin
3.5
CVSSv2
CVE-2019-17433
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
Laravel-admin Laravel-admin 1.7.3
4.3
CVSSv2
CVE-2015-4127
Cross-site scripting (XSS) vulnerability in the church_admin plugin prior to 0.810 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.
Church Admin Project Church Admin
1 EDB exploit
4.3
CVSSv2
CVE-2019-17606
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and previous versions for Node.js is vulnerable to stored XSS via the content of a post.
Hexo-admin Project Hexo-admin
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »