Vulnerabilities
Vulnerable Software
Naviwebs:  >> Navigate Cms  >> 2.9.4  Security Vulnerabilities
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
CVSS Score
4.9
EPSS Score
0.671
Published
2022-04-28
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVSS Score
5.4
EPSS Score
0.002
Published
2022-01-19


Contact Us

Shodan ® - All rights reserved