Dsmall Project
Dsmall Project Dsmall: vulnerabilities and CVEs
Dsmall Project Dsmall has 6 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9307 | Medium (6.1) | 0.68% | — | Apr 4, 2018 | dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. |
| CVE-2018-9017 | Medium (5.4) | 0.54% | — | Mar 25, 2018 | dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. |
| CVE-2018-9016 | Medium (6.1) | 0.68% | — | Mar 25, 2018 | dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. |
| CVE-2018-9015 | Medium (5.4) | 0.54% | — | Mar 25, 2018 | dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box). |
| CVE-2018-9014 | High (7.5) | 1.1% | — | Mar 25, 2018 | dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. |
| CVE-2018-8906 | Medium (6.1) | 0.68% | — | Mar 22, 2018 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html. |