Vignette

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 12
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2018-18941

    In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued.

    Last Modified: Nov 21, 2024
    Published: Jan 31, 2019

    CVE-2008-6412

    Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.

    Last Modified: Apr 23, 2026
    Published: Mar 06, 2009

    CVE-2004-0917

    The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.

    Last Modified: Apr 16, 2026
    Published: Nov 19, 2004

    CVE-2002-0385

    Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output.

    Last Modified: Apr 16, 2026
    Published: Apr 16, 2004

    CVE-2003-0399

    Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.

    Last Modified: Apr 16, 2026
    Published: Jun 11, 2003
    Items Per Page
    Vignette Vulnerabilities & Security CVEs | CVE-DB