Vulnerabilities > Phpipam > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-19 CVE-2022-23045 Cross-site Scripting vulnerability in PHPipam 1.4.4
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings.
network
phpipam CWE-79
3.5
2020-05-20 CVE-2020-13225 Cross-site Scripting vulnerability in PHPipam 1.4
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
network
phpipam CWE-79
3.5
2018-12-20 CVE-2018-1000860 Cross-site Scripting vulnerability in PHPipam
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single quotes.
network
high complexity
phpipam CWE-79
2.6
2018-12-20 CVE-2018-1000870 Cross-site Scripting vulnerability in PHPipam
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser.
network
phpipam CWE-79
3.5
2018-04-21 CVE-2017-15640 Cross-site Scripting vulnerability in PHPipam
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
network
phpipam CWE-79
3.5