VYPR

Apprain

by Apprain

Source repositories

CVEs (38)

  • CVE-2025-41048MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/admin…

  • CVE-2025-41047MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/ace.

  • CVE-2025-41046MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/960gr…

  • CVE-2025-41045MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[sconfig][ethical_licensekey]' parameter in /apprain/admin/config/ethical.

  • CVE-2025-41044MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Page][name]' parameter in /apprain/page/manage-static-pages/create.

  • CVE-2025-41043MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[AppReportCode][id]' and 'data[AppReportCode][name]' parameters in /apprain/appreport/manage/.

  • CVE-2025-41042MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Option][message]', 'data[Option][subject]' and 'data[Option][templatetype]' parameters in…

  • CVE-2025-41041MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]' and 'data[title]' parameters…

  • CVE-2025-41040MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]' and 'data[title]' parameters…

  • CVE-2025-41039MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[sconfig][admin_landing_page]', 'data[sconfig][currency]', 'data[sconfig][db_version]',…

  • CVE-2025-41038MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Group][name]' parameter in /apprain/admin/managegroup/add/.

  • CVE-2025-41037MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[FileManager][search]' parameter in /apprain/admin/filemanager.

  • CVE-2025-41036MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the  'data[Admin][description]', 'data[Admin][f_name]' and 'data[Admin][l_name]' parameters in…

  • CVE-2012-1153Oct 6, 2012
    risk 0.06cvss epss 0.32

    Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads…

  • CVE-2013-6058Nov 14, 2013
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.

  • CVE-2011-5229Oct 25, 2012
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

  • CVE-2011-5228Oct 25, 2012
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.

  • CVE-2011-3704Sep 23, 2011
    risk 0.00cvss epss 0.01

    appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.

Page 2 of 2