VYPR

Pagekit

by Pagekit

Source repositories

CVEs (16)

  • CVE-2022-38916CriSep 20, 2022
    risk 0.65cvss 9.8epss 0.18

    A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

  • CVE-2025-67165CriDec 17, 2025
    risk 0.64cvss 9.8epss 0.00

    An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

  • CVE-2025-67164CriDec 17, 2025
    risk 0.64cvss 9.9epss 0.01

    An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2021-44135CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.02

    pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.

  • CVE-2023-41005HigAug 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php

  • CVE-2017-5594HigJan 25, 2017
    risk 0.45cvss 7.5epss 0.07

    An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

  • CVE-2022-36573MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.

  • CVE-2021-32245MedJun 16, 2021
    risk 0.35cvss 5.4epss 0.01

    In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to…

  • CVE-2019-16669MedSep 21, 2019
    risk 0.35cvss 5.3epss 0.01

    The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.

  • CVE-2018-11564MedJun 2, 2018
    risk 0.34cvss 4.8epss 0.03

    Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or…

  • CVE-2018-14381MedJul 18, 2018
    risk 0.33cvss 6.1epss 0.01

    Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.

  • CVE-2026-6983MedApr 25, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is…

  • CVE-2026-6652MedApr 20, 2026
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutralization of directives in dynamically…

  • CVE-2024-45967MedOct 1, 2024
    risk 0.31cvss 4.7epss 0.00

    Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.

  • CVE-2026-57518HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in…

  • CVE-2019-19013HigNov 22, 2019
    risk 0.00cvss 8.8epss 0.01

    A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.