Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2023-50011

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
Attacker Value
Unknown

CVE-2023-5910

Disclosure Date: November 02, 2023 (last updated November 09, 2023)
A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-244229 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2022-47766

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
Attacker Value
Unknown

CVE-2021-28070

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
Attacker Value
Unknown

CVE-2020-19547

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
Attacker Value
Unknown

CVE-2020-18065

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
Attacker Value
Unknown

CVE-2020-21357

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
Attacker Value
Unknown

CVE-2020-21356

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
Attacker Value
Unknown

CVE-2019-18815

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
PopojiCMS 2.0.1 allows refer= Open Redirection.
Attacker Value
Unknown

CVE-2019-18816

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.