← Back

Showdoc

showdoc

Vendor: Showdoc • 41 CVEs

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Showdoc
1Showdoc
Nov 21, 2024
Jan 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
1Showdoc
1Showdoc
Nov 21, 2024
Jan 22, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
1Showdoc
1Showdoc
Nov 21, 2024
Jan 3, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
1Showdoc
1Showdoc
Nov 21, 2024
Dec 26, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Dec 3, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to URL Redirection to Untrusted Site
1Showdoc
1Showdoc
Nov 21, 2024
Dec 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Dec 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Dec 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
1Showdoc
1Showdoc
Nov 21, 2024
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to URL Redirection to Untrusted Site
1Showdoc
1Showdoc
Nov 21, 2024
Nov 13, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Nov 13, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Nov 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Showdoc
1Showdoc
Nov 21, 2024
Oct 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
1Showdoc
1Showdoc
Nov 21, 2024
Sep 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.
1Showdoc
1Showdoc
Nov 21, 2024
Aug 4, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
1Showdoc
1Showdoc
Nov 21, 2024
Aug 4, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
showdoc is vulnerable to Missing Cryptographic Step
1Showdoc
1Showdoc
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
1Showdoc
1Showdoc
Nov 21, 2024
Nov 28, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
1Showdoc
1Showdoc
Nov 21, 2024
Nov 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
1Showdoc
1Showdoc
Nov 21, 2024
Nov 22, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.