CVE-2020-37053
- EPSS 0.01%
- Veröffentlicht 30.01.2026 22:07:19
- Zuletzt bearbeitet 13.02.2026 17:52:30
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by u...
CVE-2020-37054
- EPSS 0.01%
- Veröffentlicht 30.01.2026 22:07:19
- Zuletzt bearbeitet 13.02.2026 17:51:05
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leverag...
CVE-2020-23242
- EPSS 0.29%
- Veröffentlicht 26.07.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:13:40
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
CVE-2020-23243
- EPSS 0.21%
- Veröffentlicht 26.07.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:13:40
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
CVE-2021-37473
- EPSS 0.68%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:14
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.
CVE-2021-37475
- EPSS 0.68%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:15
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
CVE-2021-37476
- EPSS 0.68%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:15
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
CVE-2021-37477
- EPSS 0.68%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:15
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
CVE-2021-37478
- EPSS 0.68%
- Veröffentlicht 26.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:15
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
CVE-2020-23654
- EPSS 0.21%
- Veröffentlicht 26.08.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:58
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."