Show filters
233 Total Results
Displaying 61-70 of 233
Sort by:
Attacker Value
Unknown

CVE-2020-36607

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Attacker Value
Unknown

CVE-2020-20589

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Attacker Value
Unknown

CVE-2022-45278

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
Attacker Value
Unknown

CVE-2022-44140

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
Attacker Value
Unknown

CVE-2021-29334

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html
Attacker Value
Unknown

CVE-2022-4014

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.
Attacker Value
Unknown

CVE-2022-43320

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
Attacker Value
Unknown

CVE-2022-3771

Disclosure Date: October 31, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The identifier VDB-212501 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-41496

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
Attacker Value
Unknown

CVE-2022-40408

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.