Home/Product/croogo
Product

croogo

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-42718
all versions
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in
6.5MEDIUM
CVE-2024-29643
all versions
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
9.1CRITICAL
CVE-2021-44673
all versions
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user
8.8HIGH
CVE-2019-20789
<= 3.0.6
Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
4.8MEDIUM
CVE-2019-7173
<= 3.0.5
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title f
4.8MEDIUM
CVE-2019-7171
<= 3.0.5
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title f
4.8MEDIUM
CVE-2019-7170
<= 3.0.5
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title f
4.8MEDIUM
CVE-2019-7169
<= 3.0.5
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title f
4.8MEDIUM
CVE-2019-7168
<= 3.0.5
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog fi
4.8MEDIUM
CVE-2017-1000510
all versions
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of
5.4MEDIUM
CVE-2015-1053
<= 2.2.0
Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject ar
CVE-2014-8577
<= 2.0.0
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script o
threatengine.sh