Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-55417 1 Thecontrolgroup 1 Voyager 2026-02-26 4.3 Medium
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
CVE-2024-55416 1 Thecontrolgroup 1 Voyager 2025-05-23 3.5 Low
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
CVE-2024-55415 1 Thecontrolgroup 1 Voyager 2025-05-23 5.7 Medium
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.