Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
High

CVE-2020-7357

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Attacker Value
Unknown

CVE-2023-48202

Disclosure Date: January 27, 2024 (last updated February 01, 2024)
Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.
Attacker Value
Unknown

CVE-2023-48201

Disclosure Date: January 27, 2024 (last updated February 01, 2024)
Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.
Attacker Value
Unknown

CVE-2023-51806

Disclosure Date: January 12, 2024 (last updated January 19, 2024)
File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
Attacker Value
Unknown

CVE-2023-51350

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.
Attacker Value
Unknown

CVE-2023-3790

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235057 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-31302

Disclosure Date: June 21, 2022 (last updated October 07, 2023)
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
Attacker Value
Unknown

CVE-2020-21081

Disclosure Date: September 14, 2021 (last updated November 29, 2024)
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
Attacker Value
Unknown

CVE-2020-21082

Disclosure Date: September 14, 2021 (last updated November 29, 2024)
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.
Attacker Value
Unknown

CVE-2020-18116

Disclosure Date: August 27, 2021 (last updated November 29, 2024)
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.