Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Public Knowledge Project Subscribe
Filtered by product Open Journal Systems
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26616 1 Public Knowledge Project 1 Open Journal Systems 2022-04-11 4.3 MEDIUM 6.1 MEDIUM
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
CVE-2022-24181 1 Public Knowledge Project 1 Open Journal Systems 2022-04-08 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
CVE-2011-5196 1 Public Knowledge Project 1 Open Journal Systems 2016-09-19 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.