Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-34654

Disclosure Date: July 05, 2023 (last updated October 08, 2023)
taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2020-20725

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.
Attacker Value
Unknown

CVE-2023-1947

Disclosure Date: April 07, 2023 (last updated October 08, 2023)
A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225330 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-34167

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.
Attacker Value
Unknown

CVE-2022-48006

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.
Attacker Value
Unknown

CVE-2022-46998

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2022-36261

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt
Attacker Value
Unknown

CVE-2022-36262

Disclosure Date: August 15, 2022 (last updated October 08, 2023)
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
Attacker Value
Unknown

CVE-2021-44915

Disclosure Date: July 05, 2022 (last updated February 24, 2025)
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
Attacker Value
Unknown

CVE-2022-23880

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.