VendorsCreatiwitywitycms0.6.2
Vulnerabilities

Creatiwity WityCMS 0.6.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-12065
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.
Published 2018-06-08 · Modified
9.8EPSS 0.026
CVE-2018-14029
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.
Published 2018-07-13 · Modified
8.81 PoCEPSS 0.025
CVE-2022-29725
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-05-31 · Modified
8.8EPSS 0.014
CVE-2018-16250
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters.
Published 2019-06-20 · Modified
5.4EPSS 0.006
CVE-2018-16776
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
Published 2018-09-10 · Modified
4.8EPSS 0.007
CVE-2018-16251
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin/user/users Nickname, email, firstname, lastname, and groupe parameters.
Published 2019-06-20 · Modified
4.3EPSS 0.009