Products: 2
    Vulnerabilities: 9
    Known Exploited: 0
    4
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-4936

    Canto <= 3.0.8 - Unauthenticated Remote File Inclusion

    Last Modified: Apr 08, 2026
    Published: Jun 14, 2024

    CVE-2024-25096

    WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability

    Last Modified: Apr 28, 2026
    Published: Apr 03, 2024

    CVE-2023-3452

    Canto <= 3.0.4 - Unauthenticated Remote File Inclusion

    Last Modified: Apr 08, 2026
    Published: Aug 12, 2023

    CVE-2022-40305

    A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.

    Last Modified: Nov 21, 2024
    Published: Sep 09, 2022

    CVE-2020-28978

    The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.

    Last Modified: Nov 21, 2024
    Published: Nov 30, 2020
    Items Per Page
    Canto Vulnerabilities & Security CVEs | CVE-DB