📦 Navigate Cms

by Naviwebs

🔍 What is Navigate Cms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-23711

CRITICAL CVSS 9.8 Jun 28, 2021

NavigateCMS 2.9 contains a SQL injection vulnerability in the navigate.php file via the URL-encoded GET parameter 'category'. This allows attackers to execute arbitrary SQL commands on the database. A...

CVE-2020-37053

HIGH CVSS 7.1 Jan 30, 2026

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability in the 'sidx' parameter of comments functionality. Attackers with valid credentials can exploit this to extract database inform...

CVE-2021-44351

HIGH CVSS 7.5 Jan 6, 2022

This vulnerability allows attackers to read arbitrary files on NavigateCMS servers by manipulating the 'id' parameter in the navigate_download.php script. It affects all NavigateCMS 2.9 installations,...

CVE-2021-36455

HIGH CVSS 8.8 Aug 6, 2021

This SQL injection vulnerability in Navigate CMS allows attackers to execute arbitrary SQL commands through the quicksearch parameter in the comments module. It affects all users running Navigate CMS ...

CVE-2020-14017

HIGH CVSS 7.5 Jun 24, 2020

Navigate CMS 2.9 r1433 stores session data in cleartext files in /private/sessions directory, allowing unauthenticated attackers to brute-force or directly view active sessions. This exposes CSRF toke...

CVE-2020-14015

HIGH CVSS 7.5 Jun 24, 2020

This vulnerability in Navigate CMS allows an attacker to reset any user's password without proper authentication. By exploiting a flaw in the password reset mechanism where no activation code is suppl...