← Back

Navigatecms

navigatecms

Vendor: Naviwebs • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Nov 21, 2024
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend databas...Show more
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.Show less
1Naviwebs
1Navigatecms
Nov 21, 2024
Aug 26, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
1Naviwebs
1Navigatecms
Nov 21, 2024
Aug 26, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
1Naviwebs
1Navigatecms
Nov 21, 2024
Aug 26, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
1Naviwebs
1Navigatecms
Nov 21, 2024
Aug 26, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
1Naviwebs
1Navigatecms
Nov 21, 2024
Jun 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.cla...Show more
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.Show less