Vulnerabilities > Mojoportal > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-09 CVE-2023-24323 XXE vulnerability in Mojoportal 2.7.0.0
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
network
low complexity
mojoportal CWE-611
8.8
2022-09-30 CVE-2022-40341 Unrestricted Upload of File with Dangerous Type vulnerability in Mojoportal 2.7.0.0
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.
network
low complexity
mojoportal CWE-434
8.8