CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-41046 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41046
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/960grid.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41047 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41047
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/ace.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41048 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41048
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/admin.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41049 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41049
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41050 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41050
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/base_libs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41051 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41051
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/bootstrap.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41052 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41052
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/canvasjs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41053 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41053
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/commonresource.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41054 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41054
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/cycle.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41055 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41055
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/dialogs.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41056 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41056
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/hysontable.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41057 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41057
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/rich_text_editor.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41058 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41058
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/row_manager.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41059 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41059
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tablesorter.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41060 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41060
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tree.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41061 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41061
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/uploadify.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41062 - Reflected Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41062
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41063 - Reflected Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41063
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7385 - SQL Injection in GOV CMS

CVE ID : CVE-2025-7385
Published : Sept. 4, 2025, 1:15 p.m. | 1 hour, 50 minutes ago
Description : Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7388 - Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

CVE ID : CVE-2025-7388
Published : Sept. 4, 2025, 1:15 p.m. | 1 hour, 50 minutes ago
Description : It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property with inadequate input validation leading to OS command injection.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8311 - dotCMS Boolean-based Blind SQL Injection Vulnerability

CVE ID : CVE-2025-8311
Published : Sept. 4, 2025, 2:12 p.m. | 53 minutes ago
Description : dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, which was directly concatenated into a SQL query without proper sanitization. Exploitation allowed an authenticated attacker with low privileges to extract data from database, perform privilege escalation, or trigger denial-of-service conditions. The vulnerability was verified using tools such as SQLMap and confirmed to allow full database exfiltration and potential denial-of-service conditions via crafted payloads. The vulnerability is fixed in the following versions of dotCMS stack: 25.08.14 / 25.07.10-1v2 LTS / 24.12.27v10 LTS / 24.04.24v21 LTS
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...