Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-22549

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
Attacker Value
Unknown

CVE-2024-22548

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
Attacker Value
Unknown

CVE-2023-52074

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.
Attacker Value
Unknown

CVE-2023-52073

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.
Attacker Value
Unknown

CVE-2023-52072

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.
Attacker Value
Unknown

CVE-2024-21732

Disclosure Date: January 01, 2024 (last updated January 09, 2024)
FlyCms through abbaa5a allows XSS via the permission management feature.
Attacker Value
Unknown

CVE-2020-36065

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save.
Attacker Value
Unknown

CVE-2020-19613

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.