Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-50011
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
0
Attacker Value
Unknown
CVE-2023-5910
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-244229 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2022-47766
Disclosure Date: January 19, 2023 (last updated October 08, 2023)
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
0
Attacker Value
Unknown
CVE-2021-28070
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
0
Attacker Value
Unknown
CVE-2020-19547
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
0
Attacker Value
Unknown
CVE-2020-18065
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
0
Attacker Value
Unknown
CVE-2020-21357
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
0
Attacker Value
Unknown
CVE-2020-21356
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
0
Attacker Value
Unknown
CVE-2019-18815
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
PopojiCMS 2.0.1 allows refer= Open Redirection.
0
Attacker Value
Unknown
CVE-2019-18816
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.
0