Vulnerabilities > Onenav

DATE CVE VULNERABILITY TITLE RISK
2024-01-07 CVE-2023-7210 Improper Authentication vulnerability in Onenav
A vulnerability was found in OneNav up to 0.9.33.
network
low complexity
onenav CWE-287
critical
9.8
2022-03-12 CVE-2022-26276 Path Traversal vulnerability in Onenav 0.9.14
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
network
low complexity
onenav CWE-22
5.3
2021-08-16 CVE-2021-38712 Exposure of Resource to Wrong Sphere vulnerability in Onenav 0.9.12
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents.
network
low complexity
onenav CWE-668
7.5
2021-08-05 CVE-2021-38138 Cross-site Scripting vulnerability in Onenav 0.9.12
OneNav beta 0.9.12 allows XSS via the Add Link feature.
network
low complexity
onenav CWE-79
5.4