Luke Towers
21 exploits
Active since Jun 2020
OctoberCMS <1.0.466 - Info Disclosure
CVSS 4.8
Winter CMS < 1.2.3 - Authenticated Stored Cross-Site Scripting via SVG Logo Upload
CVSS 2.0
Winter CMS < 1.2.3 - Authenticated Stored Cross-Site Scripting via SVG Logo Upload
CVSS 2.0
October CMS 1.0.319-1.0.465 - Stored Cross-Site Scripting via Markdown FormWidget
CVSS 3.5
October CMS 1.0.319-1.0.465 - Stored Cross-Site Scripting via Markdown FormWidget
CVSS 3.5
October CMS debugbar <3.1.0 - Info Disclosure
CVSS 6.1
OctoberCMS <1.0.468 - Info Disclosure
CVSS 6.1
October CMS <1.0.469 - Info Disclosure
CVSS 7.5
October CMS <1.0.470 - Privilege Escalation
CVSS 4.0
October CMS 1.0.319-1.0.469 - Stored Cross-Site Scripting via SVG File Upload
CVSS 2.8
October CMS 1.0.469 - Authenticated Arbitrary PHP Execution via Twig Sandbox Escape
CVSS 5.2
October 1.0.319-1.0.467 - Stored Cross-Site Scripting via Froala Rich Editor Paste
CVSS 3.7
OctoberCMS <1.0.466 - Privilege Escalation
CVSS 6.2
OctoberCMS 1.0.319-1.0.465 - Authenticated Arbitrary File Upload via Asset Manager
CVSS 3.4
OctoberCMS 1.0.319-1.0.465 - Reflected Cross-Site Scripting via CSV Import
CVSS 4.0
OctoberCMS 1.0.319-1.0.465 - CSV Injection via ImportExportController
CVSS 4.0
OctoberCMS 1.0.319-1.0.465 - CSV Injection via ImportExportController
CVSS 4.0
Winter < 1.2.4 - Stored Cross-Site Scripting via Media Manager File Rename
CVSS 2.0
Winter < 1.2.4 - Stored Cross-Site Scripting via ColorPicker FormWidget
CVSS 2.0
Winter <1.2.3 - Local File Inclusion
CVSS 3.3
Winter CMS < 1.2.10 - Authenticated Stored Cross-Site Scripting via SVG Upload