VendorsNaviwebsnavigate_cmsany version
Vulnerabilities

Naviwebs Navigate any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-13796
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.
Published 2020-06-03 · Modified
6.1EPSS 0.007
CVE-2020-13797
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.
Published 2020-06-03 · Modified
6.1EPSS 0.007
CVE-2020-13798
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.
Published 2020-06-03 · Modified
6.1EPSS 0.007
CVE-2018-18029
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
Published 2018-10-09 · Modified
5.4EPSS 0.006
CVE-2020-13795
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
Published 2020-06-03 · Modified
5.3EPSS 0.018