The Elefant CMS
93%
Total Score
80
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2017-20064 elefant/cms is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.3.13. | 0.0.0 - 1.3.13 | High |
CVE-2017-20061 elefant/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.3.13. | 0.0.0 - 1.3.13 | Medium |
CVE-2017-20060 elefant/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.3.13. | 0.0.0 - 1.3.13 | Medium |
CVE-2017-20062 elefant/cms is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 1.3.13. | 0.0.0 - 1.3.13 | High |
CVE-2017-20057 elefant/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.3.13. | 0.0.0 - 1.3.13 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pda/pheanstalk Version ^4.0 | — | — |
google/apiclient Version ^2.12.1 | — | — |
chillerlan/php-qrcode Version ^4.3 | — | — |
pragmarx/google2fa-qrcode Version ^3.0 | — | — |
bshaffer/oauth2-server-php Version ^1.10 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant