Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-41652

    Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

    Last Modified: Nov 21, 2024
    Published: Mar 01, 2022

    CVE-2021-27679

    Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Last Modified: Nov 21, 2024
    Published: Mar 11, 2021

    CVE-2021-27678

    Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Last Modified: Nov 21, 2024
    Published: Mar 11, 2021

    CVE-2021-27677

    Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.

    Last Modified: Nov 21, 2024
    Published: Mar 11, 2021

    CVE-2020-35734

    Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitrary user's data (username, displayed name, etc.). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Last Modified: Nov 21, 2024
    Published: Feb 15, 2021
    Items Per Page
    Batflat Vulnerabilities & Security CVEs | CVE-DB