Skip to main content

Vendor/product archive

ss-proj / shirasagi CVEs

Beta · best-effort

12 CVEs tagged to ss-proj / shirasagi0 Critical, 2 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2024-46898

Published Oct 15, 2024

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41889

Published Sep 15, 2023

SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a secur…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38569

Published Sep 5, 2023

Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36492

Published Sep 5, 2023

Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39448

Published Sep 5, 2023

Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code ex…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22427

Published Feb 24, 2023

Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22425

Published Feb 24, 2023

Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43499

Published Dec 5, 2022

Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary scr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43479

Published Dec 5, 2022

Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29485

Published Jun 14, 2022

Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5607

Published Jul 10, 2020

Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6009

Published Sep 12, 2019

Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1