Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-46041 | A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the pa A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add). NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-37732 | Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file. Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file. NVD description · AI analysis pending | 6.1 | 17% | PoC |
| — | |
| CVE-2024-29499 +1 in the same advisory: …29338 | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2. Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2. NVD description · AI analysis pending | 7.4 group max | <1% | PoC |
| — | |
| CVE-2022-25576 | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts. NVD description · AI analysis pending | 4.5 | <1% | PoC |
| — | |
| CVE-2021-46253 | A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML. A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2021-44116 | Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-23342 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. NVD description · AI analysis pending | 8.8 | 12% | PoC ×2 |
| — | |
| CVE-2020-12071 | Anchor 0.12.7 allows admins to cause XSS via crafted post content. Anchor 0.12.7 allows admins to cause XSS via crafted post content. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2018-7251 | An issue was discovered in config/error.php in Anchor 0.12.3. An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred. NVD description · AI analysis pending | 9.8 | 72% |
| — |