Vulnerabilities (CVE)

Filtered by vendor Vocabularyserver Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14343 1 Vocabularyserver 1 Tematres 2024-02-28 3.5 LOW 5.4 MEDIUM
TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
CVE-2019-14345 1 Vocabularyserver 1 Tematres 2024-02-28 7.5 HIGH 9.8 CRITICAL
TemaTres 3.0 allows remote unprivileged users to create an administrator account
CVE-2019-14344 1 Vocabularyserver 1 Tematres 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkReplace URI.