Travianz Project maintains a single web-based trading and strategy-game application that exhibits a pattern of input-handling and cryptographic weaknesses, including code injection, cross-site scripting, improper authorization, and the use of weak random-number generation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Travianz Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36994CRITICAL In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code. | Jul 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-36993CRITICAL The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.paramete | Jul 7, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-36992HIGH PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code. | Jul 7, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-36995MEDIUM TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie. | Jul 6, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Travianz Project.
Media articles that mention a CVE ID that affects a product developed by Travianz Project — matched by CVE ID, not by vendor name.