NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85559  CVE-2017-8385  Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.    Medium  2017-05-27  2017-05-11  View
85557  CVE-2017-8383  Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.    Medium  2017-05-27  2017-05-11  View
86708  CVE-2017-9516  Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.    3.5  Low  2017-06-17  2017-06-14  View
10295  CVE-2011-3723  Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files.    Medium  2017-01-07  2012-03-13  View
3702  CVE-2008-3840  Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.    Medium  2017-01-03  2009-01-29  View

Page 2691 of 17672, showing 5 records out of 88360 total, starting on record 13451, ending on 13455

Actions