Search
Search Results (9 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-52608 | 1 Reportico | 1 Reportico | 2026-08-24 | 9.8 Critical |
| An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | ||||
| CVE-2026-52610 | 1 Reportico | 1 Reportico | 2026-08-24 | 9.1 Critical |
| An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint. | ||||
| CVE-2026-52607 | 1 Reportico | 1 Reportico | 2026-08-24 | 6.5 Medium |
| A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint. | ||||
| CVE-2026-52606 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php. | ||||
| CVE-2026-52609 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | ||||
| CVE-2024-31556 | 1 Reportico | 1 Reportico | 2026-04-15 | 7.8 High |
| An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function. | ||||
| CVE-2023-48865 | 1 Reportico | 1 Reportico | 2025-06-17 | 6.5 Medium |
| An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL. | ||||
| CVE-2014-3777 | 1 Reportico | 1 Php Report Designer | 2025-04-12 | N/A |
| Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter. | ||||
| CVE-2023-46925 | 1 Reportico | 1 Reportico | 2024-11-21 | 4.8 Medium |
| Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS). | ||||
Page 1 of 1.