Vulnerabilities (CVE)

Filtered by vendor Adive Subscribe
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-4336 1 Adive 1 Framework 2025-10-15 N/A 7.6 HIGH
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user.
CVE-2024-4337 1 Adive 1 Framework 2025-10-15 N/A 7.6 HIGH
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.
CVE-2020-7991 1 Adive 1 Framework 2024-11-21 6.8 MEDIUM 8.8 HIGH
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
CVE-2020-7990 1 Adive 1 Framework 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Adive Framework 2.0.8 has admin/user/add userName XSS.
CVE-2020-7989 1 Adive 1 Framework 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Adive Framework 2.0.8 has admin/user/add userUsername XSS.