Vulnerabilities (CVE)

Filtered by vendor Piwigo Subscribe
Filtered by product Lexiglot
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-8943 1 Piwigo 1 Lexiglot 2020-06-02 6.5 MEDIUM 8.8 HIGH
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
CVE-2014-8942 1 Piwigo 1 Lexiglot 2020-06-02 6.8 MEDIUM 8.8 HIGH
Lexiglot through 2014-11-20 allows CSRF.
CVE-2014-8938 1 Piwigo 1 Lexiglot 2020-06-02 2.1 LOW 7.8 HIGH
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.
CVE-2014-8937 1 Piwigo 1 Lexiglot 2020-06-02 5.0 MEDIUM 7.5 HIGH
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.