Filtered by vendor Showdoc Subscriptions
Filtered by product Showdoc Subscriptions
Total 41 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-0941 1 Showdoc 1 Showdoc 2022-03-18 5.4 Medium
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0946 1 Showdoc 1 Showdoc 2022-03-18 5.4 Medium
Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0409 1 Showdoc 1 Showdoc 2022-03-01 7.8 High
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
CVE-2022-0362 1 Showdoc 1 Showdoc 2022-02-02 9.8 Critical
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
CVE-2021-4172 1 Showdoc 1 Showdoc 2022-01-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2022-0079 1 Showdoc 1 Showdoc 2022-01-10 5.3 Medium
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2021-4168 1 Showdoc 1 Showdoc 2022-01-06 8.8 High
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4000 1 Showdoc 1 Showdoc 2021-12-07 6.1 Medium
showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-3993 1 Showdoc 1 Showdoc 2021-12-02 6.5 Medium
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4017 1 Showdoc 1 Showdoc 2021-12-02 8.8 High
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3989 1 Showdoc 1 Showdoc 2021-12-02 6.1 Medium
showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-3990 1 Showdoc 1 Showdoc 2021-12-02 6.5 Medium
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-3683 1 Showdoc 1 Showdoc 2021-11-16 6.5 Medium
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3775 1 Showdoc 1 Showdoc 2021-11-16 5.4 Medium
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3776 1 Showdoc 1 Showdoc 2021-11-16 5.4 Medium
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41745 1 Showdoc 1 Showdoc 2021-10-27 9.8 Critical
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
CVE-2021-36440 1 Showdoc 1 Showdoc 2021-09-15 9.8 Critical
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.
CVE-2021-3678 1 Showdoc 1 Showdoc 2021-08-11 5.9 Medium
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2018-19609 1 Showdoc 1 Showdoc 2018-12-21 N/A
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
CVE-2018-19433 1 Showdoc 1 Showdoc 2018-12-18 N/A
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.