spina
CMS
Activity
- Latest release
- 3mo ago
- Total releases
- 79
- Cadence
- ~18 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Mar 04, 2015
| Version | Released | |
|---|---|---|
2.21.0
minor
|
2.21.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.20.0
minor
|
2.20.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.19.0
minor
|
2.19.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.18.0
minor
1 CVE
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev |
2.18.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.17.0
minor
1 CVE
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev |
2.17.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.16.0
minor
1 CVE
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev |
2.16.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.15.1
patch
1 CVE
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev |
2.15.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.15.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.15.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.14.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.14.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.13.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.13.1
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
2.13.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.13.0
minor
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
2.12.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.12.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.11.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.11.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.10.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.10.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.9.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.9.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.9.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.9.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.8.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.8.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.8.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.8.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.7.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.7.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.6.2
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.6.2
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.6.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.6.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.6.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.6.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.5.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.5.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.4.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.3.5
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.5
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.3.4
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.4
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.3.3
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.3
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.3.2
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.2
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.3.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.3.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
2.2.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.2.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.1.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.1.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.2
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.2
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.0.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.0.0
major
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.0
major
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
2.0.0.beta
pre
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.0.beta
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
1.2.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.2.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.alpha
pre
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.0.alpha
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
1.1.4
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.1.4
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.1.3
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.1.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.1.2
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.1.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.1.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.1.1
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
1.1.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.1.0
minor
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
1.0.3
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.0.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.0.2
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.0.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.0.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.0.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.0.0
major
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
1.0.0
major
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.12.0
minor
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.12.0
minor
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.1
patch
2 CVEs
CVE-2024-7106
GHSA-wqw3-p83g-r24v
Jul 25, 2024
Cross-Site Request Forgery in Spina
Medium
Network
Low
None
None
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 64 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
References Updated Aug 14, 2024 · Source: OSV.dev
CVE-2023-3445
GHSA-97wh-6hmj-g8j9
Jun 28, 2023
Spina Cross-site Scripting vulnerability
3.5
/ 10
Low
Network
Low
High
Required
Unchanged
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. Affected versions
0.10.0
0.11.0
0.11.1
0.12.0
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
+ 60 more Show less
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
0.6.24
0.6.25
0.6.26
0.6.27
0.6.28
0.6.29
0.7.0
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
2.0.0
2.0.0.alpha
2.0.0.beta
2.0.1
2.0.2
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.13.1
2.14.0
2.15.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.15.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.11.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|