ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-15148
A flaw has been found in CmsEasy up to 7.7.7.

A flaw has been found in CmsEasy up to 7.7.7. Affected is the function savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Page. Executing a manipulation of the argument content/tempdata can lead to code injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.0<1% PoC
  • cmseasy cmseasy
CVE-2025-11332
A vulnerability was determined in CmsEasy up to 7.7.7.

A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler. Executing a manipulation of the argument PHP_SELF can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.0<1% PoC
  • cmseasy cmseasy
CVE-2025-55910
CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.

CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.

NVD description · AI analysis pending
6.3<1% PoC
  • cmseasy cmseasy
CVE-2025-1336
+1 in the same advisory: …1335
A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic.

A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admin.php. The manipulation of the argument imgname leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.31% PoC
  • cmseasy cmseasy
CVE-2025-1106
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9.

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • cmseasy cmseasy
CVE-2025-0973
A vulnerability classified as critical was found in CmsEasy 7.7.7.9.

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument select[] leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • cmseasy cmseasy
CVE-2024-34315
+1 in the same advisory: …34314
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/templat

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • cmseasy cmseasy
CVE-2024-31551
Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

NVD description · AI analysis pending
7.5<1%
  • cmseasy cmseasy
CVE-2024-32236
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

NVD description · AI analysis pending
3.5<1% PoC
  • cmseasy cmseasy
CVE-2024-32163
+1 in the same advisory: …32162
CMSeasy 7.7.7.9 is vulnerable to code execution.

CMSeasy 7.7.7.9 is vulnerable to code execution.

NVD description · AI analysis pending
6.4
group max
<1% PoC
  • cmseasy cmseasy
CVE-2024-25828
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

NVD description · AI analysis pending
4.9<1% PoC
  • cmseasy cmseasy
CVE-2024-0523
A vulnerability was found in CmsEasy up to 7.7.7.

A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250693 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
9.8<1% PoC
  • cmseasy cmseasy
CVE-2020-18406
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.

An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.

NVD description · AI analysis pending
7.5<1% PoC
  • cmseasy cmseasy
CVE-2023-34880
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php.

cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

NVD description · AI analysis pending
9.81% PoC
  • cmseasy cmseasy
CVE-2021-42643
+1 in the same advisory: …42644
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability.

cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

NVD description · AI analysis pending
8.8
group max
2% PoC
  • cmseasy cmseasy
CVE-2019-8434
+1 in the same advisory: …8432
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.

In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • cmseasy cmseasy
CVE-2018-11679
+1 in the same advisory: …11680
An issue was discovered in CmsEasy 6.1_20180508.

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • cmseasy cmseasy