Phpkb Chadhaajay Phpkb

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Chadhaajay Phpkb.

By the Year

In 2025 there have been 0 vulnerabilities in Chadhaajay Phpkb. Phpkb did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 119 4.84
2019 0 0.00
2018 0 0.00

It may take a day or so for new Phpkb vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Chadhaajay Phpkb Security Vulnerabilities

CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10478 8.8 - High - March 12, 2020

CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.

Session Riding

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10446 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-category.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10447 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-failed-login.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10449 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10450 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-traffic.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10451 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-user.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10452 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/save-article.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10453 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/search-users.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10454 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/sitemap-generator.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10455 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/translate.php by adding a question mark (?) followed by the payload.

XSS

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10456 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/trash-box.php by adding a question mark (?) followed by the payload.

XSS

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10457 2.7 - Low - March 12, 2020

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).

Directory traversal

Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10458 6.5 - Medium - March 12, 2020

Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (../) via the GET parameter crdir, when the GET parameter action is set to df, causing a Denial of Service.

Directory traversal

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files

CVE-2020-10459 2.7 - Low - March 12, 2020

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.

Directory traversal

admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10460 4.9 - Medium - March 12, 2020

admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.

CSV Injection

The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10461 6.1 - Medium - March 12, 2020

The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php, via the GET parameter cmt.

XSS

Reflected XSS in admin/edit-field.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10462 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10463 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10464 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10465 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10466 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-comment.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10467 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-comment.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10468 4.8 - Medium - March 12, 2020

Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

XSS

Reflected XSS in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10469 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10470 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10471 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10472 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10473 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10474 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10475 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10493 4.3 - Medium - March 12, 2020

CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.

Session Riding

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10448 4.8 - Medium - March 12, 2020

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php by adding a question mark (?) followed by the payload.

XSS

Reflected XSS in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10476 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

Reflected XSS in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10477 4.8 - Medium - March 12, 2020

Reflected XSS in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

XSS

CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10504 4.3 - Medium - March 12, 2020

CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.

Session Riding

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10503 4.3 - Medium - March 12, 2020

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.

Session Riding

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10502 4.3 - Medium - March 12, 2020

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.

Session Riding

CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10501 6.5 - Medium - March 12, 2020

CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.

Session Riding

CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10500 4.3 - Medium - March 12, 2020

CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.

Session Riding

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10499 4.3 - Medium - March 12, 2020

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

Session Riding

CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10498 6.5 - Medium - March 12, 2020

CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.

Session Riding

CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10497 6.5 - Medium - March 12, 2020

CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.

Session Riding

CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10496 4.3 - Medium - March 12, 2020

CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.

Session Riding

CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10495 4.3 - Medium - March 12, 2020

CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.

Session Riding

CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10494 4.3 - Medium - March 12, 2020

CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.

Session Riding

CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10482 4.3 - Medium - March 12, 2020

CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.

Session Riding

CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10485 4.3 - Medium - March 12, 2020

CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.

Session Riding

CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10484 4.3 - Medium - March 12, 2020

CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.

Session Riding

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10483 4.3 - Medium - March 12, 2020

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

Session Riding

CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9

CVE-2020-10480 4.3 - Medium - March 12, 2020

CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.

Session Riding

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Chadhaajay Phpkb or by Chadhaajay? Click the Watch button to subscribe.

Chadhaajay
Vendor

subscribe