Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 46 results


CVE-2022-26847

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Vulnerable Vulnerable Fixed Not affected
Show less packages

CVE-2022-26846

Medium priority

Some fixes available 2 of 5

SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Vulnerable Vulnerable Fixed Not affected
Show less packages

CVE-2022-23638

Medium priority
Vulnerable

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Vulnerable Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2021-44123

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44122

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44120

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2021-44118

Medium priority

Some fixes available 3 of 4

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2020-28984

Medium priority

Some fixes available 1 of 4

prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Needs evaluation Fixed Needs evaluation
Show less packages

CVE-2019-19830

Medium priority

Some fixes available 1 of 3

_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Fixed Not affected
Show less packages

CVE-2019-16394

Medium priority

Some fixes available 1 of 4

SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Fixed Vulnerable
Show less packages