NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 85559 | CVE-2017-8385 | Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
| 85557 | CVE-2017-8383 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | 2 | 5 | Medium | 2017-05-27 | 2017-05-11 | View | |
| 86708 | CVE-2017-9516 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-14 | View | |
| 10295 | CVE-2011-3723 | Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
| 3702 | CVE-2008-3840 | Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2691 of 17672, showing 5 records out of 88360 total, starting on record 13451, ending on 13455