Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity XWikiplatform Other Vulnerability (CVE-2025-32783) CVE-2025-32783 Medium XWikiplatform URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-32970) CVE-2025-32970 CWE-601 CWE-601 Medium XWikiplatform Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-31464) CVE-2024-31464 CWE-916 CWE-916 Medium XWiki Transmission of Private Resources into a New Sphere ('Resource Leak') Vulnerability (CVE-2023-38509) CVE-2023-38509 CWE-402 CWE-402 Medium XWiki Uncontrolled Resource Consumption Vulnerability (CVE-2024-21651) CVE-2024-21651 CWE-400 CWE-400 Medium XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23618) CVE-2022-23618 CWE-601 CWE-601 Medium XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-29204) CVE-2023-29204 CWE-601 CWE-601 Medium XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-32068) CVE-2023-32068 CWE-601 CWE-601 Medium XXE in Ivanti Connect Secure, Policy Secure and Neurons (CVE-2024-22024) CVE-2024-22024 CWE-112 CWE-112 Medium YetiForce CRM Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-4092) CVE-2021-4092 CWE-352 CWE-352 Medium YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4111) CVE-2021-4111 CWE-20 CWE-20 Medium YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4117) CVE-2021-4117 CWE-20 CWE-20 Medium YetiForce CRM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2023-49508) CVE-2023-49508 CWE-22 CWE-22 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4107) CVE-2021-4107 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4116) CVE-2021-4116 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4121) CVE-2021-4121 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-1340) CVE-2022-1340 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2829) CVE-2022-2829 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2885) CVE-2022-2885 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2890) CVE-2022-2890 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2924) CVE-2022-2924 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3000) CVE-2022-3000 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3002) CVE-2022-3002 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3004) CVE-2022-3004 CWE-707 CWE-707 Medium YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3005) CVE-2022-3005 CWE-707 CWE-707 Medium YetiForce CRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-1411) CVE-2022-1411 CWE-434 CWE-434 Medium Yii2 debug toolkit CWE-200 CWE-200 Medium Yii2 Gii extension CWE-200 CWE-200 Medium Yii2 weak secret key CWE-693 CWE-693 Medium Yii debug mode enabled CWE-16 CWE-16 Medium Yii running in dev mode CWE-16 CWE-16 Medium YOURLS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3824) CVE-2011-3824 CWE-200 CWE-200 Medium YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-8488) CVE-2014-8488 CWE-707 CWE-707 Medium YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-27388) CVE-2020-27388 CWE-707 CWE-707 Medium YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3783) CVE-2021-3783 CWE-707 CWE-707 Medium YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3785) CVE-2021-3785 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4207) CVE-2010-4207 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4208) CVE-2010-4208 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4209) CVE-2010-4209 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4710) CVE-2010-4710 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-5881) CVE-2012-5881 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-5882) CVE-2012-5882 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-5883) CVE-2012-5883 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-4939) CVE-2013-4939 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-4940) CVE-2013-4940 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-4941) CVE-2013-4941 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-4942) CVE-2013-4942 CWE-707 CWE-707 Medium YUI Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-6780) CVE-2013-6780 CWE-707 CWE-707 Medium Zabbix Guest Access CWE-200 CWE-200 Medium ZenCart Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4403) CVE-2011-4403 CWE-352 CWE-352 Medium ZenCart Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4322) CVE-2009-4322 CWE-200 CWE-200 Medium ZenCart Improper Authentication Vulnerability (CVE-2009-2255) CVE-2009-2255 CWE-287 CWE-287 Medium ZenCart Improper Input Validation Vulnerability (CVE-2009-4321) CVE-2009-4321 CWE-20 CWE-20 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4547) CVE-2011-4547 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4567) CVE-2011-4567 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-0882) CVE-2015-0882 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-6578) CVE-2020-6578 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2005-3996) CVE-2005-3996 CWE-138 CWE-138 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6985) CVE-2008-6985 CWE-138 CWE-138 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6986) CVE-2008-6986 CWE-138 CWE-138 Medium Zenphoto Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5595) CVE-2015-5595 CWE-352 CWE-352 Medium Zenphoto Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0993) CVE-2012-0993 CWE-94 CWE-94 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2008-6925) CVE-2008-6925 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-4562) CVE-2009-4562 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-4563) CVE-2009-4563 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4907) CVE-2010-4907 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-0995) CVE-2012-0995 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-2641) CVE-2012-2641 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4519) CVE-2012-4519 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-7241) CVE-2013-7241 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2948) CVE-2015-2948 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2949) CVE-2015-2949 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5592) CVE-2015-5592 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5593) CVE-2015-5593 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5594) CVE-2015-5594 CWE-707 CWE-707 Medium 1...106107108 107 / 108