10
I Use This!
Inactive
Analyzed about 24 hours ago. based on code collected 2 days ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2024-42718 BDSA-2024-10902 Medium Dec 26, 2025 A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' para more...
4.0.7, 4.0.6, 4.0.5, 4.0.4, 4.0.3, 4.0.2, 3.0.7, 4.0.1, 1.3.6, 1.4.6
BDSA-2024-4641 Medium Jul 23, 2024 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file ` more...
BDSA-2021-4038 High Jan 18, 2022 Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict more...
BDSA-2021-4037 High Jan 18, 2022 Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict more...
BDSA-2021-4036 High Jan 18, 2022 Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict more...
BDSA-2021-4035 High Jan 18, 2022 Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict more...
BDSA-2021-3669 Medium Dec 07, 2021 Croogo is vulnerable to remote code execution (RCE) due to unsafe file upload functionality. An authenticated attacker with administrator credentials c more...