Show filters
5,501 Total Results
Displaying 1-10 of 5,501
Sort by:
Attacker Value
Moderate
CVE-2021-39609
Disclosure Date: August 23, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
3
Attacker Value
Very High
CVE-2023-41892
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
3
Attacker Value
High
CVE-2022-26352
Disclosure Date: July 17, 2022 (last updated October 07, 2023)
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.
3
Attacker Value
Moderate
CVE-2019-9053
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
3
Attacker Value
Moderate
CVE-2021-41947
Disclosure Date: October 08, 2021 (last updated November 28, 2024)
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
2
Attacker Value
Very High
CVE-2022-38812
Disclosure Date: August 31, 2022 (last updated October 08, 2023)
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
1
Attacker Value
Unknown
CVE-2020-23630
Disclosure Date: January 11, 2021 (last updated November 28, 2024)
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
1
Attacker Value
Unknown
CVE-2021-3018
Disclosure Date: January 05, 2021 (last updated November 28, 2024)
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
1
Attacker Value
Moderate
CVE-2020-25538
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
1
Attacker Value
Moderate
CVE-2020-25557
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
1