Product
kohanaframework kohana
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-8979
CVE-2014-8684
CVE-2016-10510
<= 3.3.6
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
all versions
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session c
<= 3.3.5
Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitr