← Back

Status

status

8 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Statusnet
statusnet
Powerbpm
powerbpm

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Status
1Powerbpm
Jun 17, 2026
Jun 2, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to...Show more
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.Show less
1Status
1Statusnet
Nov 21, 2024
Feb 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
1Status
1Statusnet
Nov 21, 2024
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
1Status
1Statusnet
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
1Status
1Statusnet
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
statusnet before 0.9.9 has XSS
1Status
1React Native Desktop
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
1Status
1Statusnet
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
1Status
1Statusnet
Apr 29, 2026
Sep 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other fil...Show more
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.Show less