Vulnerabilities > Publify Project > Publify > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-29 CVE-2023-0569 Unspecified vulnerability in Publify Project Publify
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
network
low complexity
publify-project
6.5
2023-01-14 CVE-2022-2815 Unspecified vulnerability in Publify Project Publify
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
network
low complexity
publify-project
6.5
2022-05-23 CVE-2022-1811 Unrestricted Upload of File with Dangerous Type vulnerability in Publify Project Publify
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
network
low complexity
publify-project CWE-434
5.4
2022-05-23 CVE-2022-1810 Unspecified vulnerability in Publify Project Publify
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
network
low complexity
publify-project
4.3
2022-05-16 CVE-2022-0574 Incorrect Authorization vulnerability in Publify Project Publify
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
network
low complexity
publify-project CWE-863
6.5
2022-05-16 CVE-2022-0578 Unspecified vulnerability in Publify Project Publify
Code Injection in GitHub repository publify/publify prior to 9.2.8.
network
low complexity
publify-project
6.5
2022-05-16 CVE-2022-1553 Incorrect Authorization vulnerability in Publify Project Publify
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8.
network
low complexity
publify-project CWE-863
4.9
2021-11-10 CVE-2021-25974 Cross-site Scripting vulnerability in Publify Project Publify
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS.
network
low complexity
publify-project CWE-79
5.4
2021-11-10 CVE-2021-25975 Cross-site Scripting vulnerability in Publify Project Publify
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload.
network
low complexity
publify-project CWE-79
5.4
2021-11-02 CVE-2021-25973 Incorrect Resource Transfer Between Spheres vulnerability in Publify Project Publify
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control.
network
low complexity
publify-project CWE-669
6.5