Ss Proj maintains Shirasagi, a content-management system that appears prominently in the vulnerability landscape relative to its focused product scope. The vendor's disclosures cluster around a single, widely deployed platform without a clear concentration of recurring weakness classes; defenders tracking this product should monitor releases for structural changes in its exposure surface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ss Proj over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39448HIGH Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code exe | Sep 5, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-46898HIGH SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the serve | Oct 15, 2024 | 7.5 | 23 | NO | NO |
CVE-2022-43479MEDIUM Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack. | Dec 5, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-29485MEDIUM Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. | Jun 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2019-6009MEDIUM Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | Sep 12, 2019 | 6.1 | 22 | NO | NO |
CVE-2022-43499MEDIUM Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary scri | Dec 5, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-36492MEDIUM Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user wh | Sep 5, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-22425MEDIUM Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script. | Feb 24, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-38569MEDIUM Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is | Sep 5, 2023 | 5.4 | 18 | NO | NO |
CVE-2020-5607MEDIUM Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | Jul 10, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ss Proj.
Media articles that mention a CVE ID that affects a product developed by Ss Proj — matched by CVE ID, not by vendor name.