← Back

Sickrage

sickrage

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Sickrage
sickrage

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sickrage
1Sickrage
Jun 17, 2026
Apr 12, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a use...Show more
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.Show less
1Sickrage
1Sickrage
Jun 17, 2026
Apr 12, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary Jav...Show more
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside the application, and possibly steal a user’s sensitive information.Show less
1Sickrage
1Sickrage
Jun 17, 2026
Mar 31, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.