Show filters
141 Total Results
Displaying 1-10 of 141
Sort by:
Attacker Value
Unknown

CVE-2024-13193

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-4595

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263317 was assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-25422

Disclosure Date: February 28, 2024 (last updated February 15, 2025)
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
Attacker Value
Unknown

CVE-2024-24291

Disclosure Date: February 06, 2024 (last updated February 14, 2024)
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
Attacker Value
Unknown

CVE-2024-22567

Disclosure Date: February 05, 2024 (last updated February 15, 2024)
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
Attacker Value
Unknown

CVE-2023-51282

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
Attacker Value
Unknown

CVE-2023-52274

Disclosure Date: January 11, 2024 (last updated January 17, 2024)
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
Attacker Value
Unknown

CVE-2023-48864

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
Attacker Value
Unknown

CVE-2023-50578

Disclosure Date: December 30, 2023 (last updated January 09, 2024)
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
Attacker Value
Unknown

CVE-2023-50563

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.