← Back

Statusnet

statusnet

Vendor: Status • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Status
1Statusnet
Nov 21, 2024
Feb 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
1Status
1Statusnet
Nov 21, 2024
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
1Status
1Statusnet
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
1Status
1Statusnet
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
statusnet before 0.9.9 has XSS
1Status
1Statusnet
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
1Status
1Statusnet
Apr 29, 2026
Sep 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other fil...Show more
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.Show less