Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pixie vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-4710
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 up to and including 1.04 allow remote malicious users to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
Lucidcrew Pixie 1.04
Lucidcrew Pixie 1.03
Getpixie Pixie 1.01a
Getpixie Pixie 1.01
Lucidcrew Pixie 1.02
1 EDB exploit
9.8
CVSSv3
CVE-2019-10766
Pixie versions 1.0.x prior to 1.0.3, and 2.0.x prior to 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
Pixie Project Pixie
10
CVSSv3
CVE-2017-12905
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote malicious users to disclose information or execute arbitrary code via the url parameter to Launderer.php.
Vebto Pixie - Image Editor 1.4
Vebto Pixie - Image Editor 1.7
9.8
CVSSv3
CVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
Lucidcrew Pixie 1.04
1 EDB exploit
NA
CVE-2014-3786
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote malicious users to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
Lucidcrew Pixie 1.04
NA
CVE-2011-3793
Pixie 1.04 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
Lucidcrew Pixie 1.04
6.1
CVSSv3
CVE-2017-7359
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
Lucidcrew Pixie 1.04
6.1
CVSSv3
CVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
Lucidcrew Pixie 1.04
6.1
CVSSv3
CVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
Lucidcrew Pixie 1.04
6.1
CVSSv3
CVE-2017-7362
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
Lucidcrew Pixie 1.04
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »