📦 Flusity

by Flusity

🔍 What is Flusity?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-31666

CRITICAL CVSS 9.8 Apr 22, 2024

This critical vulnerability in flusity-CMS v2.33 allows remote attackers to execute arbitrary code on affected systems by sending specially crafted scripts to the edit_addon_post.php component. Attack...

CVE-2024-32418

CRITICAL CVSS 9.8 Apr 22, 2024

This vulnerability in flusity CMS v2.33 allows remote attackers to execute arbitrary code through the add_addon.php component, leading to complete system compromise. It affects all systems running the...

CVE-2024-25502

CRITICAL CVSS 9.8 Feb 15, 2024

CVE-2024-25502 is a critical directory traversal vulnerability in flusity CMS v2.4 that allows remote attackers to execute arbitrary code and access sensitive files via the download_backup.php compone...

CVE-2024-26350

HIGH CVSS 8.8 Feb 22, 2024

Flusity-CMS v2.33 contains a Cross-Site Request Forgery vulnerability in the contact form settings update component. This allows attackers to trick authenticated administrators into making unauthorize...

CVE-2024-26352

HIGH CVSS 8.8 Feb 22, 2024

Flusity-CMS v2.33 contains a CSRF vulnerability in the /core/tools/add_places.php component that allows attackers to trick authenticated administrators into performing unauthorized actions. This affec...

CVE-2024-25417

HIGH CVSS 8.8 Feb 11, 2024

Flusity-CMS v2.33 contains a CSRF vulnerability in the translation management component that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects a...

CVE-2024-25419

HIGH CVSS 8.8 Feb 11, 2024

Flusity-CMS v2.33 contains a CSRF vulnerability in the update_menu.php component that allows attackers to trick authenticated administrators into performing unauthorized menu updates. This affects all...

CVE-2024-24468

HIGH CVSS 8.8 Feb 5, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in flusity-CMS v2.33 allows remote attackers to execute arbitrary code via the add_customblock.php endpoint. This affects all users running the vulner...

CVE-2024-24524

HIGH CVSS 8.8 Feb 2, 2024

This CSRF vulnerability in flusity-CMS v2.33 allows attackers to trick authenticated administrators into executing arbitrary code by visiting malicious web pages. Attackers can compromise the entire C...