Mojoportal
Mojoportal: vulnerabilidades y CVE
Mojoportal tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses1
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-69770 | Crítica (10) | 0.67% | — | 13 feb 2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file. |
| CVE-2025-28367 | Media (6.5) | 1.9% | — | 21 abr 2025 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. |
| CVE-2023-44012 | Media (6.1) | 1.3% | — | 2 oct 2023 | Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component. |
| CVE-2023-44011 | Crítica (9.8) | 1.8% | — | 2 oct 2023 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. |
| CVE-2023-44009 | Crítica (9.8) | 1.8% | — | 2 oct 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. |
| CVE-2023-44008 | Crítica (9.8) | 1.6% | — | 2 oct 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. |
| CVE-2023-24689 | Media (4.3) | 0.73% | — | 9 feb 2023 | An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx |
| CVE-2023-24688 | Media (5.3) | 0.70% | — | 9 feb 2023 | An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. |
| CVE-2023-24687 | Media (5.4) | 0.63% | — | 9 feb 2023 | Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2023-24323 | Alta (8.8) | 1.2% | — | 9 feb 2023 | Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. |
| CVE-2023-24322 | Media (6.1) | 32% | — | 9 feb 2023 | A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi… |
| CVE-2022-40123 | Media (6.5) | 1.2% | — | 3 oct 2022 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system. |
| CVE-2022-40341 | Alta (8.8) | 1.4% | — | 30 sept 2022 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. |
| CVE-2018-7447 | Media (4.8) | 0.69% | — | 24 feb 2018 | mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable.… |
| CVE-2017-1000457 | Media (4.8) | 0.82% | — | 2 ene 2018 | Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.