Search CVE reports


Toggle filters

21 – 30 of 63 results


CVE-2023-28426

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: GHSA-xrqq-wqh4-5hg2. Reason: Further investigation showed that this CVE was assigned in error. Notes: See https://github.com/darylldoyle/svg-sanitizer/issues/88 for a...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Not affected Not affected
Show less packages

CVE-2023-27372

Medium priority

Some fixes available 2 of 7

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Vulnerable Fixed Fixed
Show less packages

CVE-2023-24258

Medium priority

Some fixes available 2 of 7

SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Vulnerable Fixed Fixed
Show less packages

CVE-2022-37155

Medium priority

Some fixes available 1 of 6

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Vulnerable Not affected Fixed
Show less packages

CVE-2022-28961

Medium priority

Some fixes available 1 of 6

Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Not affected Not affected Fixed
Show less packages

CVE-2022-28960

High priority

Some fixes available 1 of 6

A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Not affected Not affected Fixed
Show less packages

CVE-2022-28959

Medium priority

Some fixes available 1 of 6

Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below allows attackers to execute arbitrary web scripts or HTML.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Not affected Not affected Fixed
Show less packages

CVE-2022-26847

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Vulnerable Vulnerable Fixed
Show less packages

CVE-2022-26846

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Not affected Vulnerable Vulnerable Fixed
Show less packages

CVE-2022-23638

Medium priority

Some fixes available 1 of 9

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no...

1 affected package

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
spip Vulnerable Vulnerable Not affected Not affected
Show less packages