Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-25693

    ResourceSpace 8.6 SQL Injection via collection_edit.php

    Last Modified: Jul 15, 2026
    Published: Apr 12, 2026

    CVE-2019-25662

    ResourceSpace 8.6 SQL Injection via watched_searches.php

    Last Modified: Apr 15, 2026
    Published: Apr 05, 2026

    CVE-2022-31260

    In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.

    Last Modified: Nov 21, 2024
    Published: Jul 17, 2022

    CVE-2021-41950

    A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.

    Last Modified: Nov 21, 2024
    Published: Nov 15, 2021

    CVE-2021-41765

    A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server.

    Last Modified: Nov 21, 2024
    Published: Nov 15, 2021
    Items Per Page