Filtered by vendor Craftercms Subscriptions
Total 25 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-15684 1 Craftercms 1 Crafter Cms 2024-11-21 7.5 High
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.
CVE-2017-15683 1 Craftercms 1 Crafter Cms 2024-11-21 8.6 High
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
CVE-2017-15682 1 Craftercms 1 Crafter Cms 2024-11-21 6.1 Medium
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
CVE-2017-15681 1 Craftercms 1 Crafter Cms 2024-11-21 9.8 Critical
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
CVE-2017-15680 1 Craftercms 1 Crafter Cms 2024-11-21 6.5 Medium
In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.