VYPR

Piwik

by Matomo

CVEs (4)

  • CVE-2025-34104CriJul 15, 2025
    risk 0.64cvss epss 0.01

    An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to…

  • CVE-2013-0195MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.

  • CVE-2013-0194MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.

  • CVE-2013-0193MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.