Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-37732

Disclosure Date: June 24, 2024 (last updated February 26, 2025)
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
Attacker Value
Unknown

CVE-2022-25576

Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.
Attacker Value
Unknown

CVE-2021-46253

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2021-44116

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
Attacker Value
Unknown

CVE-2020-23342

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
Attacker Value
Unknown

CVE-2015-5060

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
0
Attacker Value
Unknown

CVE-2015-5687

Disclosure Date: October 05, 2015 (last updated October 05, 2023)
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
0
Attacker Value
Unknown

CVE-2014-9182

Disclosure Date: December 02, 2014 (last updated October 05, 2023)
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
0
Attacker Value
Unknown

CVE-2013-5099

Disclosure Date: August 09, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
0