ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-46041
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the pa

A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).

NVD description · AI analysis pending
5.4<1% PoC
  • anchorcms anchor cms
CVE-2024-37732
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

NVD description · AI analysis pending
6.117% PoC
  • anchorcms anchor cms
CVE-2024-29499
+1 in the same advisory: …29338
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • anchorcms anchor cms
CVE-2022-25576
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php.

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.

NVD description · AI analysis pending
4.5<1% PoC
  • anchorcms anchor cms
CVE-2021-46253
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.

A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.

NVD description · AI analysis pending
5.4<1% PoC
  • anchorcms anchor cms
CVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php.

Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.

NVD description · AI analysis pending
6.1<1% PoC
  • anchorcms anchor cms
CVE-2020-23342
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

NVD description · AI analysis pending
8.812% PoC ×2
  • anchorcms anchor cms
CVE-2020-12071
Anchor 0.12.7 allows admins to cause XSS via crafted post content.

Anchor 0.12.7 allows admins to cause XSS via crafted post content.

NVD description · AI analysis pending
4.8<1% PoC
  • anchorcms anchor
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3.

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

NVD description · AI analysis pending
9.872%
  • anchorcms anchor