Chronoengine
Products
2- 3 CVEs
- 3 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-27459 | Med | 0.40 | 6.1 | 0.01 | Nov 16, 2020 | Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed. | ||
| CVE-2021-28377 | Med | 0.35 | 5.3 | 0.08 | Jan 12, 2022 | ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files. | ||
| CVE-2022-47135 | Med | 0.28 | 4.3 | 0.00 | May 25, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions. | ||
| CVE-2021-28376 | Low | 0.18 | 2.7 | 0.01 | Jan 12, 2022 | ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files. | ||
| CVE-2008-0567 | 0.06 | — | 0.34 | Feb 5, 2008 | Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3)… | |||
| CVE-2026-58148 | Hig | 0.00 | — | 0.00 | Jul 17, 2026 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability. |
- risk 0.40cvss 6.1epss 0.01
Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.
- risk 0.35cvss 5.3epss 0.08
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions.
- risk 0.18cvss 2.7epss 0.01
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
- CVE-2008-0567Feb 5, 2008risk 0.06cvss —epss 0.34
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3)…
- risk 0.00cvss —epss 0.00
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.