Vulnerabilities (CVE)

Filtered by vendor Naviwebs Subscribe
Filtered by product Navigate Cms
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17553 1 Naviwebs 1 Navigate Cms 2024-11-21 6.5 MEDIUM 8.8 HIGH
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php.
CVE-2018-17552 1 Naviwebs 1 Navigate Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.