Vulnerabilities
36 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-4329 | A vulnerability was found in 74CMS up to 3.33.0. A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-46089 | 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. NVD description · AI analysis pending | 6.3 | <1% | PoC |
| — | |
| CVE-2024-2561 | A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the function sendCompanyLogo of the file /controller/company/Index.php#sendCompanyLogo of the component Company Logo Handler. The manipulation of the argument imgBase64 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257060. NVD description · AI analysis pending | 8.8 | 6% | PoC |
| — | |
| CVE-2022-42154 | An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-33095 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. NVD description · AI analysis pending | 7.5 group max | 1% | PoC |
| — | |
| CVE-2022-29721 +1 in the same advisory: …29720 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2022-26271 | 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php. 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php. NVD description · AI analysis pending | 7.5 | 5% | PoC |
| — | |
| CVE-2020-22421 | 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key. 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-22208 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. NVD description · AI analysis pending | 9.8 | 10% | PoC |
| — | |
| CVE-2020-35339 | In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/function In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2020-29279 | PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code ex PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution. NVD description · AI analysis pending | 9.8 | 53% | PoC ×2 |
| — | |
| CVE-2019-17612 | An issue was discovered in 74CMS v5.2.8. An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2019-11374 | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. NVD description · AI analysis pending | 8.8 | 10% | PoC ×3 |
| — | |
| CVE-2019-10684 | Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-20519 | An issue was discovered in 74cms v4.2.111. An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter. NVD description · AI analysis pending | 8.1 | 1% | PoC |
| — | |
| CVE-2018-20454 | An issue was discovered in 74cms v4.2.111. An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |