Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2020-36492

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-36491

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-36494

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36495

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36496

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.
Attacker Value
Unknown

CVE-2020-36490

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-23044

Disclosure Date: October 22, 2021 (last updated November 29, 2024)
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Attacker Value
Unknown

CVE-2020-22937

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
Attacker Value
Unknown

CVE-2020-25042

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.
Attacker Value
Unknown

CVE-2020-24223

Disclosure Date: August 30, 2020 (last updated February 22, 2025)
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.