screetsec
6 exploits
Active since Dec 2020
Automad < 1.10.9 - Stored Cross-Site Scripting via Sitename Parameter
CVSS 2.4
automad < 1.10.9 - Unrestricted File Upload via FileCollectionController.php
CVSS 4.7
Automad < 1.10.9 - Server-Side Request Forgery via FileController Import URL
CVSS 6.3
automad < 1.10.9 - Cross-Site Request Forgery in User Creation Handler
CVSS 4.3
Victor CMS 1.0 - SQL Injection via Search Parameter
CVSS 9.8
Daily Expenses Management System 1.0 - 'item' SQL Injection