CVE-2025-52353
- EPSS 0.13%
- Veröffentlicht 26.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 18:55:07
An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed vi...
CVE-2023-38970
- EPSS 0.3%
- Veröffentlicht 30.08.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:33
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.
CVE-2023-38971
- EPSS 0.33%
- Veröffentlicht 29.08.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:33
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add new rack function.
CVE-2023-38969
- EPSS 0.33%
- Veröffentlicht 28.08.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:32
Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function.
CVE-2023-38973
- EPSS 0.08%
- Veröffentlicht 25.08.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:33
A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
CVE-2023-38974
- EPSS 0.08%
- Veröffentlicht 25.08.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:33
A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
CVE-2022-41705
- EPSS 5.95%
- Veröffentlicht 25.11.2022 18:15:10
- Zuletzt bearbeitet 29.04.2025 15:15:48
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
CVE-2022-41711
- EPSS 10%
- Veröffentlicht 25.10.2022 21:15:49
- Zuletzt bearbeitet 07.05.2025 20:15:22
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.