Product
pagekit
15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-67165
CVE-2025-67164
CVE-2024-45967
CVE-2023-41005
CVE-2022-38916
CVE-2022-36573
CVE-2021-44135
CVE-2021-32245
CVE-2019-19013
CVE-2019-16669
CVE-2018-14381
CVE-2018-11564
CVE-2017-5594
CVE-2014-8070
CVE-2014-8069
all versions
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
all versions
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to
all versions
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
all versions
An issue in Pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction func
all versions
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
all versions
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a
<= 1.0.18
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
all versions
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scrip
all versions
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
all versions
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user ac
< 1.0.14
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
<= 1.0.13
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user wi
<= 1.0.10
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered us
all versions
Open redirect vulnerability in YOOtheme Pagekit CMS 0.8.7 allows remote attackers to redirect users to arbitrary web sites and con
all versions
Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web s