Showing 2 vulnerabilities on this page for Navigate CMS

Signals CISA KEV Ransomware Nuclei
Naviwebs S.C. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Navigate CMS 2.8.7 - Cross-Site Request Forgery

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

CWE-352Jan 30, 2026
CVSS5.1v4.0EPSS0.203%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Navigate CMS 2.8.7 - ''sidx' SQL Injection

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.

CWE-89Jan 30, 2026
CVSS7.1v4.0EPSS0.338%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX