Magnolia
Products
6- 10 CVEs
- 6 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46362 | Cri | 0.64 | 9.8 | 0.05 | Feb 11, 2022 | A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter. | ||
| CVE-2021-46361 | Cri | 0.64 | 9.8 | 0.03 | Feb 11, 2022 | An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload. | ||
| CVE-2013-4621 | Cri | 0.64 | 9.8 | 0.02 | Dec 27, 2019 | Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities | ||
| CVE-2021-46366 | Hig | 0.57 | 8.8 | 0.01 | Feb 11, 2022 | An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials. | ||
| CVE-2021-46365 | Hig | 0.51 | 7.8 | 0.02 | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file. | ||
| CVE-2021-46364 | Hig | 0.51 | 7.8 | 0.02 | Feb 11, 2022 | A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file. | ||
| CVE-2021-46363 | Hig | 0.51 | 7.8 | 0.02 | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel. | ||
| CVE-2022-33098 | Med | 0.47 | 6.1 | 0.52 | Jul 7, 2022 | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture. | ||
| CVE-2021-25894 | Med | 0.40 | 6.1 | 0.01 | Apr 2, 2021 | Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter. | ||
| CVE-2021-25893 | Med | 0.35 | 5.4 | 0.01 | Apr 2, 2021 | Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/. | ||
| CVE-2026-18478 | Med | 0.33 | — | 0.00 | Aug 10, 2026 | Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10 | ||
| CVE-2013-4759 | 0.03 | — | 0.04 | Aug 9, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email parameter to… | |||
| CVE-2005-4361 | 0.03 | — | 0.02 | Dec 20, 2005 | Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |||
| CVE-2008-1953 | 0.00 | — | 0.01 | Apr 25, 2008 | Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are… | |||
| CVE-2008-0701 | 0.00 | — | 0.01 | Feb 12, 2008 | ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content. |
- risk 0.64cvss 9.8epss 0.05
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
- risk 0.64cvss 9.8epss 0.03
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
- risk 0.64cvss 9.8epss 0.02
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
- risk 0.57cvss 8.8epss 0.01
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.
- risk 0.51cvss 7.8epss 0.02
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.
- risk 0.51cvss 7.8epss 0.02
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
- risk 0.51cvss 7.8epss 0.02
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.
- risk 0.47cvss 6.1epss 0.52
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
- risk 0.40cvss 6.1epss 0.01
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.
- risk 0.35cvss 5.4epss 0.01
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.
- risk 0.33cvss —epss 0.00
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10
- CVE-2013-4759Aug 9, 2013risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email parameter to…
- CVE-2005-4361Dec 20, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
- CVE-2008-1953Apr 25, 2008risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are…
- CVE-2008-0701Feb 12, 2008risk 0.00cvss —epss 0.01
ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.