Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-37732
Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
0
Attacker Value
Unknown
CVE-2022-25576
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.
0
Attacker Value
Unknown
CVE-2021-46253
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.
0
Attacker Value
Unknown
CVE-2021-44116
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
0
Attacker Value
Unknown
CVE-2020-23342
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
0
Attacker Value
Unknown
CVE-2015-5060
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
0
Attacker Value
Unknown
CVE-2015-5687
Disclosure Date: October 05, 2015 (last updated October 05, 2023)
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
0
Attacker Value
Unknown
CVE-2014-9182
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
0
Attacker Value
Unknown
CVE-2013-5099
Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
0