| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-11404 | File Upload Bypass in django Filer | django CMS Association | django Filer | Medium | 5.5 | 2024-11-20 11:55:25 | Deep Dive |
| CVE-2024-52600 | Statamic CMS has Path Traversal in Asset Upload | statamic | cms | Medium | 5.3 | 2024-11-19 16:30:12 | Deep Dive |
| CVE-2024-11319 | Stored XSS in Open Source Project "django-cms" | django CMS Association | django-cms | Medium | 4.8 | 2024-11-18 11:53:04 | Deep Dive |
| CVE-2024-52291 | Craft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution | craftcms | cms | High | 8.4 | 2024-11-13 16:12:15 | Deep Dive |
| CVE-2024-52292 | Craft Allows Attackers to Read Arbitrary System Files | craftcms | cms | High | 7.7 | 2024-11-13 16:08:33 | Deep Dive |
| CVE-2024-52293 | Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTI | craftcms | cms | High | 7.2 | 2024-11-13 16:04:52 | Deep Dive |
| CVE-2024-11175 | Public CMS Voting Management save cross site scripting | Public | CMS | Low | 3.5 | 2024-11-13 15:31:27 | Deep Dive |
| CVE-2024-10761 | Umbraco CMS Dashboard frame cross site scripting | Umbraco | CMS | Medium | 4.3 | 2024-11-04 05:00:07 | Deep Dive |
| CVE-2024-10479 | LinZhaoguan pb-cms Theme Management Module admin#themes cross site scripting | LinZhaoguan | pb-cms | Low | 2.4 | 2024-10-29 01:00:15 | Deep Dive |
| CVE-2024-10478 | LinZhaoguan pb-cms Edit Article edit cross site scripting | LinZhaoguan | pb-cms | Low | 2.4 | 2024-10-29 00:31:15 | Deep Dive |
| CVE-2024-10477 | LinZhaoguan pb-cms Permission Management Page admin#permissions cross site scripting | LinZhaoguan | pb-cms | Low | 2.4 | 2024-10-29 00:31:08 | Deep Dive |
| CVE-2024-48929 | Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:54:24 | Deep Dive |
| CVE-2024-48927 | Potential Code Execution Risk When Viewing SVG Files in Full Screen in Backoffice | umbraco | Umbraco-CMS | Medium | 4.6 | 2024-10-22 15:50:47 | Deep Dive |
| CVE-2024-48926 | Umbraco CMS logout page displayed before session expiration | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:47:33 | Deep Dive |
| CVE-2024-48925 | Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API | umbraco | Umbraco-CMS | None | 0.0 | 2024-10-22 15:27:24 | Deep Dive |
| CVE-2024-47819 | Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section | umbraco | Umbraco-CMS | Medium | 4.2 | 2024-10-22 15:25:04 | Deep Dive |
| CVE-2024-9904 | 07FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload | - | 07FLYCMS | Medium | 4.7 | 2024-10-13 01:31:04 | Deep Dive |
| CVE-2024-9903 | 07FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload | - | 07FLYCMS | Medium | 4.7 | 2024-10-12 23:00:06 | Deep Dive |
| CVE-2024-9856 | 07FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting | - | 07FLYCMS | Low | 2.4 | 2024-10-11 12:31:07 | Deep Dive |
| CVE-2024-9855 | 07FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload | - | 07FLYCMS | Medium | 4.7 | 2024-10-11 12:31:05 | Deep Dive |