Naviwebs S.C. Vulnerabilities and Affected Products
Vulnerabilities associated with Navigate CMS.
Products
Clear product- Navigate CMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37054MEDIUM | Navigate CMS 2.8.7 - Cross-Site Request ForgeryNavigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation. CWE-352Jan 30, 2026 | CVSS5.1v4.0 | EPSS0.203% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37053HIGH | Navigate CMS 2.8.7 - ''sidx' SQL InjectionNavigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts. CWE-89Jan 30, 2026 | CVSS7.1v4.0 | EPSS0.338% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |