VendorsSs-projshirasagiany version
Vulnerabilities

Ss-proj Shirasagi any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2023-39448
Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.
Published 2023-09-05 · Modified
8.8EPSS 0.013
CVE-2024-46898
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.
Published 2024-10-15 · Analyzed
8.6EPSS 0.010
CVE-2019-6009
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2019-09-12 · Modified
6.1EPSS 0.019
CVE-2020-5607
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2020-07-10 · Modified
6.1EPSS 0.012
CVE-2022-29485
Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
Published 2022-06-14 · Modified
6.1EPSS 0.010
CVE-2022-43479
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.
Published 2022-12-05 · Modified
6.1EPSS 0.009
CVE-2023-36492
Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
Published 2023-09-05 · Modified
6.1EPSS 0.005
CVE-2022-43499
Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Published 2022-12-05 · Modified
5.4EPSS 0.009
CVE-2023-22425
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
Published 2023-02-24 · Modified
5.4EPSS 0.008
CVE-2023-38569
Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
Published 2023-09-05 · Modified
5.4EPSS 0.005
CVE-2023-41889
Late-Unicode normalization vulnerability in SHIRASAGI
Published 2023-09-15 · Modified
5.3EPSS 0.007
CVE-2023-22427
Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.
Published 2023-02-24 · Modified
4.8EPSS 0.008