« Volver al listado

Onenav

Onenav: vulnerabilidades y CVE

Onenav tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-88621Baja (2.7)0.31%—15 sept 2026
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file…
CVE-2026-75464Alta (8.1)0.46%—24 ago 2026
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
CVE-2025-28097Media (5.5)0.21%—28 mar 2025
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
CVE-2025-28096Media (5.4)0.23%—28 mar 2025
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
CVE-2024-33832Media (6.3)0.72%—30 abr 2024
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.
CVE-2023-7210Crítica (9.8)0.98%—7 ene 2024
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to…
CVE-2022-26276Media (5.3)1.2%—12 mar 2022
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
CVE-2021-38712Alta (7.5)1.1%—16 ago 2021
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
CVE-2021-38138Media (5.4)1.5%—5 ago 2021
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account;…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services1
  2. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.