Ushahidi

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 11
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2012-5618

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

    Last Modified: Nov 21, 2024
    Published: Feb 04, 2020

    CVE-2013-2025

    Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Last Modified: Apr 12, 2025
    Published: Apr 25, 2014

    CVE-2012-3472

    The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012

    CVE-2012-3474

    The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012

    CVE-2012-3473

    The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012
    Items Per Page
    Ushahidi Vulnerabilities & Security CVEs | CVE-DB