← Back

Easyctf

easyctf

Vendor: Kozos • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kozos
1Easyctf
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.
1Kozos
1Easyctf
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Kozos
1Easyctf
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors.