Home/Product/naviwebs navigate cms
Product

naviwebs navigate cms

34 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-37054
all versions
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions throug
4.3MEDIUM
CVE-2020-37053
all versions
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by man
7.1HIGH
CVE-2022-28117
all versions
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application
4.9MEDIUM
CVE-2021-44299
all versions
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticate
5.4MEDIUM
CVE-2021-44351
all versions
An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.
7.5HIGH
CVE-2021-36455
all versions
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
8.8HIGH
CVE-2021-36454
all versions
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php
5.4MEDIUM
CVE-2020-23243
all versions
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
4.8MEDIUM
CVE-2020-23242
all versions
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
4.8MEDIUM
CVE-2021-37478
<= 2.9.4
In NavigateCMS version 2.9.4 and below, function block is vulnerable to sql injection on parameter block-order, which results
9.8CRITICAL
CVE-2021-37477
<= 2.9.4
In NavigateCMS version 2.9.4 and below, function in structure.php is vulnerable to sql injection on parameter children_order,
9.8CRITICAL
CVE-2021-37476
<= 2.9.4
In NavigateCMS version 2.9.4 and below, function in product.php is vulnerable to sql injection on parameter id through a post
9.8CRITICAL
CVE-2021-37475
<= 2.9.4
In NavigateCMS version 2.9.4 and below, function in templates.php is vulnerable to sql injection on parameter `template-properti
9.8CRITICAL
CVE-2021-37473
<= 2.9.4
In NavigateCMS version 2.9.4 and below, function in product.php is vulnerable to sql injection on parameter products-order thr
9.8CRITICAL
CVE-2020-23711
all versions
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
9.8CRITICAL
CVE-2020-23657
all versions
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
5.4MEDIUM
CVE-2020-23656
all versions
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
5.4MEDIUM
CVE-2020-23655
all versions
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
5.4MEDIUM
CVE-2020-23654
all versions
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
5.4MEDIUM
CVE-2020-14018
all versions
An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users,
6.1MEDIUM
CVE-2020-14017
all versions
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in
7.5HIGH
CVE-2020-14016
all versions
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using eith
5.3MEDIUM
CVE-2020-14015
all versions
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that all
7.5HIGH
CVE-2020-14014
all versions
An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform s
5.4MEDIUM
CVE-2020-14927
all versions
Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.
4.8MEDIUM
CVE-2020-14067
all versions
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP a
9.8CRITICAL
CVE-2020-13798
<= 2.8.7
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.
6.1MEDIUM
CVE-2020-13797
<= 2.8.7
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/we
6.1MEDIUM
CVE-2020-13796
<= 2.8.7
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/s
6.1MEDIUM
CVE-2020-13795
<= 2.8.7
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class
5.3MEDIUM
CVE-2018-18029
all versions
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
5.4MEDIUM
CVE-2018-17849
all versions
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.
5.4MEDIUM
CVE-2018-17553
all versions
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CM
8.8HIGH
CVE-2018-17552
all versions
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user coo
9.8CRITICAL
threatengine.sh