Skip to main content

Vendor archive

canto CVEs

Beta · best-effort

9 CVEs tagged to vendor canto4 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-4936

Published Jun 14, 2024

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthentic…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25096

Published Apr 3, 2024

Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-3452

Published Aug 12, 2023

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-40305

Published Sep 9, 2022

A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28978

Published Nov 30, 2020

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28977

Published Nov 30, 2020

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28976

Published Nov 30, 2020

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /include…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24063

Published Nov 10, 2020

The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7416

Published Dec 3, 2014

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1