CVE-2024-4936
- EPSS 15.98%
- Veröffentlicht 14.06.2024 05:15:49
- Zuletzt bearbeitet 21.11.2024 09:43:54
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code...
CVE-2024-25096
- EPSS 1.24%
- Veröffentlicht 03.04.2024 13:16:02
- Zuletzt bearbeitet 10.04.2025 14:24:28
Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.
CVE-2023-3452
- EPSS 76.11%
- Veröffentlicht 12.08.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:17:17
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided t...
CVE-2022-40305
- EPSS 0.76%
- Veröffentlicht 09.09.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:21:16
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.
CVE-2020-28976
- EPSS 25.75%
- Veröffentlicht 30.11.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:25
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
CVE-2020-28977
- EPSS 10.41%
- Veröffentlicht 30.11.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:26
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.
CVE-2020-28978
- EPSS 10.41%
- Veröffentlicht 30.11.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:26
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.
CVE-2020-24063
- EPSS 0.34%
- Veröffentlicht 10.11.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:22
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.