VYPR
Vendor

Shirasagi

Products
1
CVEs
12
Across products
12
Status
Private

Products

1

Recent CVEs

12
  • CVE-2023-39448HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.

  • CVE-2023-36492MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

  • CVE-2022-43479MedDec 5, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.

  • CVE-2022-29485MedJun 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2023-38569MedSep 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

  • CVE-2023-22425MedFeb 24, 2023
    risk 0.35cvss 5.4epss 0.01

    Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.

  • CVE-2022-43499MedDec 5, 2022
    risk 0.35cvss 5.4epss 0.01

    Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2023-41889MedSep 15, 2023
    risk 0.34cvss 5.3epss 0.01

    SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The Unicode character equivalent of a…

  • CVE-2020-5607MedJul 10, 2020
    risk 0.33cvss 6.1epss 0.01

    Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2023-22427MedFeb 24, 2023
    risk 0.31cvss 4.8epss 0.01

    Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2024-46898HigOct 15, 2024
    risk 0.00cvss 7.5epss 0.01

    SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.

  • CVE-2019-6009MedSep 12, 2019
    risk 0.00cvss 6.1epss 0.02

    Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.