Vulnerabilities > Batavi > Batavi

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2011-0525 Cross-Site Request Forgery (CSRF) vulnerability in Batavi
Batavi before 1.0 has CSRF.
network
batavi CWE-352
6.8
2014-03-11 CVE-2013-2289 Cross-Site Scripting vulnerability in Batavi 1.2.2
Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to admin/index.php.
network
batavi CWE-79
4.3
2012-01-24 CVE-2012-0069 SQL Injection vulnerability in Batavi
SQL injection vulnerability in ajax.php in Batavi before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the boxToReload parameter.
network
low complexity
batavi CWE-89
7.5