VYPR

Navigatecms

by Navigatecms

Source repositories

CVEs (35)

  • CVE-2020-14014MedJun 24, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.

  • CVE-2018-18029MedOct 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.

  • CVE-2018-17849MedOct 4, 2018
    risk 0.35cvss 5.4epss 0.01

    Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.

  • CVE-2026-3317MedApr 21, 2026
    risk 0.33cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow…

  • CVE-2020-23243MedJul 26, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.

  • CVE-2020-23242MedJul 26, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.

  • CVE-2020-14927MedJun 19, 2020
    risk 0.31cvss 4.8epss 0.01

    Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.

  • CVE-2020-37054MedJan 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload…

  • CVE-2018-17552CriOct 3, 2018
    risk 0.10cvss 9.8epss 0.84

    SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.

  • CVE-2018-17553HigOct 3, 2018
    risk 0.09cvss 8.8epss 0.79

    An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php.

  • CVE-2020-14067CriJun 15, 2020
    risk 0.00cvss 9.8epss 0.01

    The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

  • CVE-2020-13798MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.

  • CVE-2020-13797MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.

  • CVE-2020-13796MedJun 3, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.

  • CVE-2020-13795MedJun 3, 2020
    risk 0.00cvss 5.3epss 0.02

    An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

Page 2 of 2