← Back

Admiror Design Studio

admiror-design-studio

5 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Admiror Design Studio
1Admiror Gallery
Jun 4, 2025
Feb 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.
1Admiror Design Studio
1Admirorframes
Nov 21, 2024
Jun 28, 2024
6.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage a...Show more
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.Show less
1Admiror Design Studio
1Admirorframes
Nov 21, 2024
Jun 28, 2024
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: b...Show more
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.Show less
1Admiror Design Studio
1Admirorframes
Nov 21, 2024
Jun 28, 2024
6.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.
1Admiror Design Studio
1Admiror Gallery
Nov 21, 2024
Aug 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.