Show filters
117 Total Results
Displaying 71-80 of 117
Sort by:
Attacker Value
Unknown

CVE-2020-19613

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
Attacker Value
Unknown

CVE-2020-35274

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
Attacker Value
Unknown

CVE-2020-20285

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
Attacker Value
Unknown

CVE-2020-23975

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
Attacker Value
Unknown

CVE-2020-23976

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
Attacker Value
Unknown

CVE-2019-16192

Disclosure Date: September 09, 2019 (last updated November 27, 2024)
upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.
Attacker Value
Unknown

CVE-2019-5967

Disclosure Date: July 05, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2019-11398

Disclosure Date: May 08, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.
0
Attacker Value
Unknown

CVE-2018-18261

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
In waimai Super Cms 20150505, there is an XSS vulnerability via the /admin.php/Foodcat/addsave fcname parameter.
0
Attacker Value
Unknown

CVE-2019-9078

Disclosure Date: February 24, 2019 (last updated November 27, 2024)
zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-case string such as sCrIpT.
0