Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2022-28036

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php
Attacker Value
Unknown

CVE-2022-28035

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php
Attacker Value
Unknown

CVE-2022-28034

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php
Attacker Value
Unknown

CVE-2022-28033

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
Attacker Value
Unknown

CVE-2022-28032

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
Attacker Value
Unknown

CVE-2022-25489

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
Attacker Value
Unknown

CVE-2022-25488

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
Attacker Value
Unknown

CVE-2022-25487

Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
Attacker Value
Unknown

CVE-2022-24223

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
Attacker Value
Unknown

CVE-2014-4852

Disclosure Date: July 10, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
0