Vendor
Creatiwity
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14029 | 0.03 | — | 0.00 | Jul 13, 2018 | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field. | |||
| CVE-2018-16776 | 0.00 | — | 0.00 | Sep 10, 2018 | wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. | |||
| CVE-2018-12065 | 0.00 | — | 0.01 | Jun 8, 2018 | A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file. |
- CVE-2018-14029Jul 13, 2018risk 0.03cvss —epss 0.00
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.
- CVE-2018-16776Sep 10, 2018risk 0.00cvss —epss 0.00
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
- CVE-2018-12065Jun 8, 2018risk 0.00cvss —epss 0.01
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.