Easyimages2.0 Project
easyimages2.0_project
8 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Dec 11, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format. |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Dec 11, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an...Show more |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page. |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via uploading a crafted PHP file. |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Nov 19, 2025 5.1 MEDIUM· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the argument File leads to cross site scrip...Show more |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Dec 25, 2023 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vulnerability affects unknown code of the file app/hide.php. The manipulation of the argument key leads...Show more |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 May 23, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 Mar 5, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7. |