Lucene search

K

Chronoengine Security Vulnerabilities

cve
cve

CVE-2008-0567

Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/...

7.7AI Score

0.016EPSS

2008-02-05 02:00 AM
37
cve
cve

CVE-2020-27459

Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.

6.1CVSS

6AI Score

0.001EPSS

2020-11-16 03:15 PM
22
cve
cve

CVE-2021-28376

ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

2.7CVSS

4.1AI Score

0.001EPSS

2022-01-12 06:15 PM
28
cve
cve

CVE-2021-28377

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

5.3CVSS

5.2AI Score

0.001EPSS

2022-01-12 06:15 PM
31
cve
cve

CVE-2022-47135

Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions.

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-25 09:15 AM
21