Florian Schmitt
12 exploits
Active since Oct 2024
YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)
CVSS 9.8
Yeswiki < 4.5.2 - Unauthenticated Path Traversal
CVSS 8.6
YesWiki < 4.4.5 - Weak Password Reset Key Hashing via Hardcoded Salt
CVSS 9.9
YesWiki <= 4.4.5 - DOM-Based Cross-Site Scripting via Tag Search Feature
CVSS 7.6
YesWiki <= 4.4.5 - Authenticated Stored Cross-Site Scripting via Attach Component
CVSS 7.6
YesWiki <= 4.4.5 - Authenticated Arbitrary File Deletion via Filemanager
CVSS 7.1
YesWiki < 4.5.4 - Stored Cross-Site Scripting via Comment Input
CVSS 5.4
YesWiki < 4.5.4 - Remote Code Execution via Arbitrary File Write
CVSS 9.8
YesWiki < 4.5.4 - Unauthenticated Backup Archive Creation and Download
CVSS 10.0
YesWiki < 4.5.4 - Reflected Cross-Site Scripting
CVSS 3.5
YesWiki < 4.5.4 - Reflected Cross-Site Scripting
CVSS 4.3
YesWiki < 4.5.4 - Reflected Cross-Site Scripting via BazaR Endpoint idformulaire Parameter
CVSS 4.3