Show filters
233 Total Results
Displaying 21-30 of 233
Sort by:
Attacker Value
Unknown

CVE-2023-46378

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
Attacker Value
Unknown

CVE-2023-43836

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
Attacker Value
Unknown

CVE-2021-38243

Disclosure Date: September 27, 2023 (last updated March 07, 2024)
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
Attacker Value
Unknown

CVE-2023-42322

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
Attacker Value
Unknown

CVE-2023-42321

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.
Attacker Value
Unknown

CVE-2023-4928

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
Attacker Value
Unknown

CVE-2023-40953

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2020-36037

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
Attacker Value
Unknown

CVE-2023-39806

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
Attacker Value
Unknown

CVE-2023-39805

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.