|
246831
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.
|
CWE-200
Information Exposure
|
CVE-2018-11327
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246832
|
4.8 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11326
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246833
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and dis…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2018-11325
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246834
|
5.9 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was ex…
|
CWE-362
Race Condition
|
CVE-2018-11324
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246835
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.
|
CWE-269
Improper Privilege Management
|
CVE-2018-11323
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246836
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11322
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246837
|
6.5 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated …
|
CWE-20
Improper Input Validation
|
CVE-2018-11321
|
2024-11-21 12:43 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246838
|
7.5 |
HIGH
Network
|
cppcms
|
cppcms
|
An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.
|
CWE-20
Improper Input Validation
|
CVE-2018-11367
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246839
|
6.1 |
MEDIUM
Network
|
loginizer
|
loginizer
|
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11366
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246840
|
7.5 |
HIGH
Network
|
pdfgen
|
pdfgen
|
jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11363
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|