Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
alfresco vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-8778
Alfresco Enterprise prior to 5.2.7 and Alfresco Community prior to 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
Alfresco Alfresco
1 EDB exploit
4.3
CVSSv2
CVE-2014-2939
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise prior to 4.1.6.13 allow remote malicious users to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.
Alfresco Alfresco
5.8
CVSSv2
CVE-2015-3366
Cross-site request forgery (CSRF) vulnerability in the Alfresco module prior to 6.x-1.3 for Drupal allows remote malicious users to hijack the authentication of arbitrary users for requests that delete an alfresco node via unspecified vectors.
Alfresco Alfresco
7.5
CVSSv2
CVE-2019-15566
The Alfresco application prior to 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
Alfresco Alfresco
9
CVSSv2
CVE-2019-14224
An issue exists in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an malicious user to achieve remote code execution on the victim machine. The attacker must upload maliciou...
Alfresco Alfresco 5.2
4.3
CVSSv2
CVE-2020-18327
Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2
Alfresco Alfresco 5.2
5
CVSSv2
CVE-2014-9302
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and previous versions allows remote malicious users to trigger outbound requests via a crafted URI in the url para...
Alfresco Community Edition
1 EDB exploit
6.5
CVSSv2
CVE-2020-25728
The Reset Password add-on prior to 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
Alfresco Reset Password
10
CVSSv2
CVE-2020-15181
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in versi...
Alfresco Reset Password
NA
CVE-2023-49964
An issue exists in Hyland Alfresco Community Edition up to and including 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restricti...
Hyland Alfresco Content Services
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »