Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Coppermine Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7186) CVE-2008-7186 CWE-264 CWE-264 Medium Core dump checker PHP script CWE-200 CWE-200 Medium Core dump file CWE-200 CWE-200 High CouchDB REST API publicly accessible CWE-285 CWE-285 High cPanel XSS (CVE-2023-29489) CVE-2023-29489 CWE-79 CWE-79 Medium Craft CMS CVE-2017-8383 Vulnerability (CVE-2017-8383) CVE-2017-8383 Medium Craft CMS CVE-2024-21622 Vulnerability (CVE-2024-21622) CVE-2024-21622 High Craft CMS Development Mode enabled CWE-200 CWE-200 Medium Craft CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-14280) CVE-2019-14280 CWE-200 CWE-200 Medium Craft CMS Files or Directories Accessible to External Parties Vulnerability (CVE-2024-52292) CVE-2024-52292 CWE-552 CWE-552 Medium Craft CMS Improper Authentication Vulnerability (CVE-2024-41800) CVE-2024-41800 CWE-287 CWE-287 High Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-27903) CVE-2021-27903 CWE-94 CWE-94 Critical Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30130) CVE-2023-30130 CWE-94 CWE-94 High Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179) CVE-2023-30179 CWE-94 CWE-94 High Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41892) CVE-2023-41892 CWE-94 CWE-94 Critical Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-23209) CVE-2025-23209 CWE-94 CWE-94 High Craft CMS Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2024-52291) CVE-2024-52291 CWE-22 CWE-22 High Craft CMS Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2024-52293) CVE-2024-52293 CWE-22 CWE-22 High Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-41824) CVE-2021-41824 CWE-1236 CWE-1236 High Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-8052) CVE-2017-8052 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-8384) CVE-2017-8384 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-9516) CVE-2017-9516 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20418) CVE-2018-20418 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-9554) CVE-2019-9554 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-12823) CVE-2019-12823 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-17496) CVE-2019-17496 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-19626) CVE-2020-19626 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-27902) CVE-2021-27902 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-32470) CVE-2021-32470 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28378) CVE-2022-28378 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37246) CVE-2022-37246 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37247) CVE-2022-37247 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37248) CVE-2022-37248 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37250) CVE-2022-37250 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-37251) CVE-2022-37251 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-2817) CVE-2023-2817 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-23927) CVE-2023-23927 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-30177) CVE-2023-30177 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-31144) CVE-2023-31144 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33194) CVE-2023-33194 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33195) CVE-2023-33195 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33196) CVE-2023-33196 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33197) CVE-2023-33197 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33495) CVE-2023-33495 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-36259) CVE-2023-36259 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-45406) CVE-2024-45406 CWE-707 CWE-707 Medium Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-9757) CVE-2020-9757 CWE-138 CWE-138 High Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-32679) CVE-2023-32679 CWE-138 CWE-138 High Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-36260) CVE-2023-36260 CWE-138 CWE-138 High Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-40035) CVE-2023-40035 CWE-138 CWE-138 High Craft CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2024-37843) CVE-2024-37843 CWE-138 CWE-138 Critical Craft CMS Missing Encryption of Sensitive Data Vulnerability (CVE-2018-20465) CVE-2018-20465 CWE-311 CWE-311 High Craft CMS Missing Encryption of Sensitive Data Vulnerability (CVE-2022-37783) CVE-2022-37783 CWE-311 CWE-311 High Craft CMS RCE (CVE-2023-41892) CVE-2023-41892 CWE-94 CWE-94 Critical Craft CMS register_argc_argv RCE (CVE-2024-56145) CVE-2024-56145 CWE-94 CWE-94 Critical Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-3814) CVE-2018-3814 CWE-434 CWE-434 High Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8385) CVE-2017-8385 CWE-640 CWE-640 Medium Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929) CVE-2019-15929 CWE-640 CWE-640 Critical Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2022-29933) CVE-2022-29933 CWE-640 CWE-640 High CRIME SSL/TLS attack CVE-2012-4929 CWE-310 CWE-310 Medium CRLF injection/HTTP response splitting (Web Server) CWE-113 CWE-113 Medium CRMEB SQL Injection (CVE-2024-36837) CVE-2024-36837 CWE-89 CWE-89 High Cross-Site Request Forgery (CSRF) (CMS Made Simple) CVE-2016-7904 CWE-352 CWE-352 Medium Cross-site Scripting CWE-79 CWE-79 High Cross-site Scripting (DOM based) CWE-79 CWE-79 High Cross-site Scripting via File Upload CWE-79 CWE-79 High Cross-site Scripting via Remote File Inclusion CWE-79 CWE-79 High Cross-site scripting vulnerability in Google Web Toolkit CVE-2012-4563 CWE-80 CWE-80 High Cross-site scripting vulnerability in Google Web Toolkit (CVE-2012-5920) CVE-2012-5920 CWE-80 CWE-80 High Cross frame scripting CWE-79 CWE-79 Medium Cross Site Scripting (Category Description) (CMS Made Simple) CVE-2017-6555 CWE-79 CWE-79 Medium Cross Site Scripting (globalmetadata) (CMS Made Simple) CVE-2017-6556 CWE-79 CWE-79 Medium Cross site scripting (requiring unencoded quote) CWE-79 CWE-79 Low Cross site scripting (XSS) in ASP.NET via ResolveUrl CWE-79 CWE-79 High Cross site scripting in HTTP-01 ACME challenge implementation CWE-79 CWE-79 High 1...20212223...306 21 / 306