Sourceforge Vulnerabilities and Affected Products
Vulnerabilities associated with Easyndexer.
Products
Clear product- 202CMS2 vulnerabilities
- Data Center Audit2 vulnerabilities
- Easyndexer2 vulnerabilities
- Echo Mirage1 vulnerability
- GPS Tracking System1 vulnerability
- Meneame English Pligg1 vulnerability
- OpenBiz Cubi Lite1 vulnerability
- phpFileManager1 vulnerability
- Placeto CMS1 vulnerability
- SimplePress CMS1 vulnerability
- Snes9K 0.0.9z1 vulnerability
- SoX - Sound eXchange1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25190MEDIUM | Easyndexer 1.0 Cross-Site Request Forgery via createuser.phpEasyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitting forged POST requests. Attackers can craft malicious web pages that submit POST requests to createuser.php with parameters including username, password, name, surname, and privileges set to 1 for administrator access. CWE-352Mar 6, 2026 | CVSS6.9v4.0 | EPSS0.13% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-25178HIGH | Easyndexer 1.0 Arbitrary File Download via showtif.phpEasyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files. CWE-22Mar 6, 2026 | CVSS8.7v4.0 | EPSS0.583% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |