Show filters
5,501 Total Results
Displaying 1-10 of 5,501
Sort by:
Attacker Value
Moderate

CVE-2021-39609

Disclosure Date: August 23, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
Attacker Value
Very High

CVE-2023-41892

Disclosure Date: September 13, 2023 (last updated October 08, 2023)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
Attacker Value
High

CVE-2022-26352

Disclosure Date: July 17, 2022 (last updated October 07, 2023)
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.
Attacker Value
Moderate

CVE-2019-9053

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
3
Attacker Value
Moderate

CVE-2021-41947

Disclosure Date: October 08, 2021 (last updated November 28, 2024)
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
Attacker Value
Very High

CVE-2022-38812

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
Attacker Value
Unknown

CVE-2020-23630

Disclosure Date: January 11, 2021 (last updated November 28, 2024)
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
Attacker Value
Unknown

CVE-2021-3018

Disclosure Date: January 05, 2021 (last updated November 28, 2024)
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
Attacker Value
Moderate

CVE-2020-25538

Disclosure Date: November 13, 2020 (last updated February 22, 2025)
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
Attacker Value
Moderate

CVE-2020-25557

Disclosure Date: November 13, 2020 (last updated February 22, 2025)
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.