← Back

Vikisolutions

vikisolutions

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Vera
vera

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vikisolutions
1Vera
Jun 17, 2026
Jan 5, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.
1Vikisolutions
1Vera
Jun 17, 2026
Jan 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application.
1Vikisolutions
1Vera
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.