Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 PACKETSTORM:218820

📄 InvoicePlane 1.6.3 Path Traversal_PACKETSTORM:218820

InvoicePlane versions 1.6.3 and below suffer from a path traversal vulnerability in the getfile method of the Guest module...

N/A N/A PACKETSTORM
HIGH 8.3 PACKETSTORM:218731

📄 Redaxo 5.20.1 Path Traversal_PACKETSTORM:218731

Redaxo versions 5.20.1 and below suffer from a path traversal vulnerability...

N/A N/A PACKETSTORM
HIGH 8.7 PACKETSTORM:218745

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218745

OpenSTAManager versions 2.9.8 and below suffer from a remote time-based SQL injection vulnerability in the Article Pricing module...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218749

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218749

OpenSTAManager versions 2.9.8 and below suffer from a remote SQL injection vulnerability in ajaxcomplete.php...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218781

📄 Shopware Improper Control_PACKETSTORM:218781

Shopware versions greater than or equal to 6.7.0.0 and less than 6.7.6.1 has an improper control related to Twig rendered views...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218746

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218746

OpenSTAManager versions 2.9.8 and below suffer from a remote SQL injection vulnerability in ajaxselect.php...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:218776

📄 OpenSTAManager 2.9.8 Cross Site Scripting_PACKETSTORM:218776

OpenSTAManager versions 2.9.8 and below suffer from a cross site scripting vulnerability in modificaiva.php via the righe parameter...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218773

📄 Authentic 8 Insecure Direct Object Reference / Broken Access Control_PACKETSTORM:218773

Authentic 8 has an broken access control that can be leveraged via insecure direct object reference that can lead to PII information disclosure...

N/A N/A PACKETSTORM
HIGH 8.5 PACKETSTORM:218764

📄 ChurchCRM Cross Site Scripting_PACKETSTORM:218764

ChurchCRM versions 6.5.2 and below suffer from a persistent cross site scripting vulnerability in the person property assignment functionality. Not...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:218771

📄 Omega-PSIR Cross Site Scripting_PACKETSTORM:218771

Omega-PSIR suffers from a cross site scripting vulnerability via the lang parameter...

N/A N/A PACKETSTORM