flusity flusity CVE Vulnerabilities (28)

CVEs: 28 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting flusity flusity (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 28 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-33442 An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component. [email protected] 4.3 1.70% 2024-05-01 2025-03-25
CVE-2024-31666 An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component. [email protected] 9.8 27.14% 2024-04-22 2025-03-28
CVE-2024-32418 An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. [email protected] 9.8 3.89% 2024-04-22 2025-04-30
CVE-2024-27757 flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "ceased its development as of February 2024." [email protected] 6.1 0.10% 2024-03-18 2025-05-05
CVE-2024-27680 Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form." [email protected] 6.1 0.13% 2024-03-04 2025-03-26
CVE-2024-27668 Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.' [email protected] 6.1 0.14% 2024-03-04 2025-03-28
CVE-2024-25410 flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php. [email protected] 6.5 0.42% 2024-02-26 2025-03-25
CVE-2024-26445 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php [email protected] 6.1 0.08% 2024-02-22 2025-03-25
CVE-2024-26352 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php [email protected] 8.8 0.11% 2024-02-22 2025-03-25
CVE-2024-26351 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php [email protected] 6.1 0.03% 2024-02-22 2025-03-25
CVE-2024-26350 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php [email protected] 8.8 0.11% 2024-02-22 2025-03-28
CVE-2024-26349 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php [email protected] 4.3 0.05% 2024-02-22 2025-03-25
CVE-2024-23094 Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_post.php [email protected] 8.8 0.11% 2024-02-22 2025-03-25
CVE-2024-26491 A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Gallery name text field. [email protected] 6.1 0.16% 2024-02-22 2025-03-25
CVE-2024-26490 A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field. [email protected] 5.4 0.15% 2024-02-22 2025-03-25
CVE-2024-26489 A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Profile Name text field. [email protected] 6.1 0.11% 2024-02-22 2025-03-13
CVE-2024-25502 Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component. [email protected] 9.8 11.43% 2024-02-15 2025-05-23
CVE-2024-25419 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php. [email protected] 8.8 0.20% 2024-02-11 2025-05-15
CVE-2024-25418 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php. [email protected] 8.8 0.15% 2024-02-11 2025-05-15
CVE-2024-25417 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php. [email protected] 8.8 0.06% 2024-02-11 2025-06-12
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence