ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
Publication date: Fri, 28 Mar 2025 00:00:00 +0000
Cyber News related to CVE-2025-28092
CVE-2025-28092 - ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. ...
8 months ago
CVE-2020-28092 - PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?gTeam&mTask&amy&status3&id,?gTeam&mTask&amy&status0&id,?gTeam&mTask&amy&status1&id,?gTeam&mTask&amy&status10&id ...
5 years ago
CVE-2023-28092 - A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could result in the system being vulnerable to exploits by attackers with physical access inside the server chassis. ...
2 years ago
CVE-2021-28092 - The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long ...
2 years ago
CVE-2024-28092 - UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.asp, or RgParentalBasic.asp. The affected fields are ...
1 year ago