Vulnerabilities > SS Proj > Shirasagi > 1.10.0

DATE CVE VULNERABILITY TITLE RISK
2024-10-15 CVE-2024-46898 Path Traversal vulnerability in Ss-Proj Shirasagi
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability.
network
low complexity
ss-proj CWE-22
7.5
2023-09-15 CVE-2023-41889 Improper Encoding or Escaping of Output vulnerability in Ss-Proj Shirasagi
SHIRASAGI is a Content Management System.
network
low complexity
ss-proj CWE-116
5.3
2023-09-05 CVE-2023-36492 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
network
low complexity
ss-proj CWE-79
6.1
2023-09-05 CVE-2023-38569 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
network
low complexity
ss-proj CWE-79
5.4
2023-09-05 CVE-2023-39448 Path Traversal vulnerability in Ss-Proj Shirasagi
Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.
network
low complexity
ss-proj CWE-22
8.8
2023-02-24 CVE-2023-22425 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
network
low complexity
ss-proj CWE-79
5.4
2023-02-24 CVE-2023-22427 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.
network
low complexity
ss-proj CWE-79
4.8
2022-12-05 CVE-2022-43499 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
network
low complexity
ss-proj CWE-79
5.4
2022-06-14 CVE-2022-29485 Cross-site Scripting vulnerability in Ss-Proj Shirasagi
Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
ss-proj CWE-79
6.1
2020-07-10 CVE-2020-5607 Open Redirect vulnerability in Ss-Proj Shirasagi
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
ss-proj CWE-601
6.1