Show filters
233 Total Results
Displaying 81-90 of 233
Sort by:
Attacker Value
Unknown

CVE-2022-31390

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.
Attacker Value
Unknown

CVE-2020-36534

Disclosure Date: June 07, 2022 (last updated February 23, 2025)
A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-27429

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.
Attacker Value
Unknown

CVE-2022-23882

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
Attacker Value
Unknown

CVE-2022-26301

Disclosure Date: March 24, 2022 (last updated February 23, 2025)
TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.
Attacker Value
Unknown

CVE-2021-44970

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
Attacker Value
Unknown

CVE-2021-44978

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Attacker Value
Unknown

CVE-2021-44977

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
Attacker Value
Unknown

CVE-2020-21236

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
Attacker Value
Unknown

CVE-2021-44349

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.