Show filters
106 Total Results
Displaying 41-50 of 106
Sort by:
Attacker Value
Unknown

CVE-2020-23580

Disclosure Date: July 08, 2021 (last updated November 28, 2024)
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
Attacker Value
Unknown

CVE-2020-20363

Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
Attacker Value
Unknown

CVE-2020-21003

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
Attacker Value
Unknown

CVE-2020-17542

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.
Attacker Value
Unknown

CVE-2021-28245

Disclosure Date: March 31, 2021 (last updated February 22, 2025)
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
Attacker Value
Unknown

CVE-2020-27848

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-35274

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
Attacker Value
Unknown

CVE-2020-17901

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
Attacker Value
Unknown

CVE-2018-16356

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
Attacker Value
Unknown

CVE-2018-16357

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.