Show filters
233 Total Results
Displaying 51-60 of 233
Sort by:
Attacker Value
Unknown

CVE-2022-46999

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserController.class.php.
Attacker Value
Unknown

CVE-2022-47766

Disclosure Date: January 19, 2023 (last updated February 24, 2025)
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
Attacker Value
Unknown

CVE-2023-0244

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the file \App\Manage\Controller\KefuController.class.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218152.
Attacker Value
Unknown

CVE-2023-0243

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-218151.
Attacker Value
Unknown

CVE-2022-40373

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.
Attacker Value
Unknown

CVE-2022-40002

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.
Attacker Value
Unknown

CVE-2022-40001

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.
Attacker Value
Unknown

CVE-2022-40000

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.
Attacker Value
Unknown

CVE-2021-36573

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.
Attacker Value
Unknown

CVE-2021-36572

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.