Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Showdoc Subscribe
Filtered by product Showdoc
Total 41 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0409 1 Showdoc 1 Showdoc 2022-02-28 6.8 MEDIUM 7.8 HIGH
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
CVE-2022-0362 1 Showdoc 1 Showdoc 2022-02-02 7.5 HIGH 9.8 CRITICAL
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
CVE-2021-4172 1 Showdoc 1 Showdoc 2022-01-27 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2022-0079 1 Showdoc 1 Showdoc 2022-01-10 5.0 MEDIUM 5.3 MEDIUM
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2021-4168 1 Showdoc 1 Showdoc 2022-01-06 6.8 MEDIUM 8.8 HIGH
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4000 1 Showdoc 1 Showdoc 2021-12-07 5.8 MEDIUM 6.1 MEDIUM
showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-3993 1 Showdoc 1 Showdoc 2021-12-02 4.3 MEDIUM 6.5 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4017 1 Showdoc 1 Showdoc 2021-12-02 6.8 MEDIUM 8.8 HIGH
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3989 1 Showdoc 1 Showdoc 2021-12-02 5.8 MEDIUM 6.1 MEDIUM
showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-3990 1 Showdoc 1 Showdoc 2021-12-02 4.3 MEDIUM 6.5 MEDIUM
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-3683 1 Showdoc 1 Showdoc 2021-11-16 4.3 MEDIUM 6.5 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3775 1 Showdoc 1 Showdoc 2021-11-16 5.8 MEDIUM 5.4 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3776 1 Showdoc 1 Showdoc 2021-11-16 5.8 MEDIUM 5.4 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41745 1 Showdoc 1 Showdoc 2021-10-26 7.5 HIGH 9.8 CRITICAL
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
CVE-2021-36440 1 Showdoc 1 Showdoc 2021-09-15 7.5 HIGH 9.8 CRITICAL
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.
CVE-2021-3678 1 Showdoc 1 Showdoc 2021-08-10 4.3 MEDIUM 5.9 MEDIUM
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2018-19620 1 Showdoc 1 Showdoc 2019-10-02 4.0 MEDIUM 4.3 MEDIUM
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
CVE-2018-19621 1 Showdoc 1 Showdoc 2018-12-26 4.3 MEDIUM 6.5 MEDIUM
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
CVE-2018-19609 1 Showdoc 1 Showdoc 2018-12-21 4.0 MEDIUM 6.5 MEDIUM
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
CVE-2018-19433 1 Showdoc 1 Showdoc 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.