Lucidcrew's vulnerability profile centers on Pixie, a modestly represented but prominent web-based application development and collaboration platform. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with recurring exposure through application-layer input-handling weaknesses including cross-site scripting, SQL injection, code injection, and improper data exposure. Defenders should prioritize patches for this vendor's web-facing deployments and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lucidcrew over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7402CRITICAL Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a | Apr 3, 2017 | 9.8 | 45 | NO | YES |
CVE-2011-4710HIGH Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP | Dec 8, 2011 | 7.5 | 31 | NO | YES |
CVE-2017-7363MEDIUM Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | Mar 31, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-7361MEDIUM Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | Mar 31, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-7362MEDIUM Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | Mar 31, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-7360MEDIUM Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | Mar 31, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-7359MEDIUM Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | Mar 31, 2017 | 6.1 | 21 | NO | NO |
CVE-2011-3793MEDIUM Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2014-3786MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTM | Jun 4, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lucidcrew.
Media articles that mention a CVE ID that affects a product developed by Lucidcrew — matched by CVE ID, not by vendor name.