Bitnami package
rum
pkg:bitnami/rum
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-50806 | Hig | 7.2 | >= 1.9.0, <= 1.9.0 | — | Jan 13, 2026 | 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific cat | |
| CVE-2021-27308 | Med | 4.8 | >= 1.8.0, < 1.8.1 | 1.8.1 | Mar 22, 2021 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter. | |
| CVE-2020-35853 | Med | 4.8 | >= 1.7.11, < 1.7.12 | 1.7.12 | Jan 26, 2021 | 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to |
- affected >= 1.9.0, <= 1.9.0
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific cat
- affected >= 1.8.0, < 1.8.1fixed 1.8.1
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
- affected >= 1.7.11, < 1.7.12fixed 1.7.12
4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to