Search
Search Results (9 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108101 | 1 Hortusfox | 1 Hortusfox | 2026-10-09 | 7.5 High |
| HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code. | ||||
| CVE-2026-108100 | 1 Hortusfox | 1 Hortusfox | 2026-10-09 | 6.5 Medium |
| HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes. | ||||
| CVE-2026-92980 | 2 Daniel Brendel, Hortusfox | 2 Hortusfox, Hortusfox | 2026-10-01 | 7.2 High |
| HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host. | ||||
| CVE-2025-45314 | 1 Hortusfox | 1 Hortusfox | 2025-08-18 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function. | ||||
| CVE-2025-45315 | 1 Hortusfox | 1 Hortusfox | 2025-08-18 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter. | ||||
| CVE-2025-45316 | 1 Hortusfox | 1 Hortusfox | 2025-08-18 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter. | ||||
| CVE-2025-45317 | 1 Hortusfox | 1 Hortusfox | 2025-08-15 | 6.5 Medium |
| A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive. | ||||
| CVE-2025-45313 | 1 Hortusfox | 1 Hortusfox | 2025-08-15 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter. | ||||
| CVE-2024-57329 | 1 Hortusfox | 1 Hortusfox | 2025-08-14 | 5.4 Medium |
| HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads. | ||||
Page 1 of 1.