Vulnerabilities

Summary — last 7 days

New vulnerabilities2,682▼ 88 vs. last week
Critical / high1,443▲ 300 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

7 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5)1.2%—Websitebaker2 Website Baker9/24/20116/16/2026
Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436.
ModifiedMedium (6.8)1.4%—Website Baker1/26/20076/16/2026
SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information.
ModifiedMedium (4.3)1.3%—Website Baker5/11/20066/16/2026
Cross-site scripting (XSS) vulnerability in Website Baker CMS before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a user display name.
ModifiedHigh (7.5)2.2%—Website Baker12/9/20056/16/2026
SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.
ModifiedMedium (5)1.4%—Website Baker8/3/20056/16/2026
Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.
ModifiedMedium (4.3)1.2%—Website Baker8/3/20056/16/2026
Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
ModifiedMedium (5)1.4%—Website Baker8/3/20056/16/2026
browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.