Qbnz Geshi vulnerabilities

5 known vulnerabilities affecting qbnz/geshi.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-2123MEDIUMCVSS 5.1≤ 1.0.9.1v1.0.9.0+1 more2025-03-09
CVE-2025-2123 [MEDIUM] CWE-79 CVE-2025-2123: A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affecte A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the file /contrib/cssgen.php of the component CSS Handler. The manipulation of the argument default-styles/keywords-1/keywords-2/keywords-3/keywords-4/comments leads to cross site scripting. The attack may be la
nvdosv
CVE-2012-3522MEDIUMCVSS 4.3≤ 1.0.8.10v1.0.8.4+5 more2014-06-13
CVE-2012-3522 [MEDIUM] CWE-79 CVE-2012-3522: Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in GeSHi before 1.0.8.11 allows remo Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in GeSHi before 1.0.8.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvdosv
CVE-2012-3521MEDIUMCVSS 5.0≤ 1.0.8.10v1.0.8.4+5 more2014-06-13
CVE-2012-3521 [MEDIUM] CWE-22 CVE-2012-3521: Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 a Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) geshi-path or (2) geshi-lang-path parameter.
nvdosv
CVE-2008-5186HIGHCVSS 7.5≥ 0, < 1.0.8.1-12008-11-21
CVE-2008-5186 [HIGH] CVE-2008-5186: The set_language_path function in geshi The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate CVE identifiers would be created for web appli
osv
CVE-2008-5185MEDIUMCVSS 5.0PoC≥ 0, < 1.0.8.1-12008-11-21
CVE-2008-5185 [MEDIUM] CVE-2008-5185: The highlighting functionality in geshi The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using "<".
osv