ZeroHour

Vulnerabilities

25 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-47990
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table

SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

NVD description · AI analysis pending
9.8<1% PoC
  • cuppacms cuppacms
CVE-2023-39681
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php.

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

NVD description · AI analysis pending
9.82% PoC
  • cuppacms cuppacms
CVE-2021-29368
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrar

Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.

NVD description · AI analysis pending
8.8<1% PoC
  • cuppacms cuppacms
CVE-2022-37190
+1 in the same advisory: …37191
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE).

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

NVD description · AI analysis pending
8.8
group max
46% PoC ×2
  • cuppacms cuppacms
CVE-2022-38296
+1 in the same advisory: …38295
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

NVD description · AI analysis pending
9.8
group max
5% PoC
  • cuppacms cuppacms
CVE-2022-34121
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

NVD description · AI analysis pending
7.54% PoC ×2
  • cuppacms cuppacms
CVE-2022-27984
+1 in the same advisory: …27985
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

NVD description · AI analysis pending
9.87% PoC
  • cuppacms cuppacms
CVE-2022-25498
+4 in the same advisory: …25495 …25486 …25485 …25497
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • cuppacms cuppacms
CVE-2022-25401
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.

NVD description · AI analysis pending
7.52% PoC
  • cuppacms cuppacms
CVE-2022-24647
Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

NVD description · AI analysis pending
8.11% PoC
  • cuppacms cuppacms
CVE-2022-24265
+2 in the same advisory: …24264 …24266
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

NVD description · AI analysis pending
7.57% PoC
  • cuppacms cuppacms
CVE-2021-3376
An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using th

An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the user_group_id_field parameter.

NVD description · AI analysis pending
8.81% PoC
  • cuppacms cuppacms
CVE-2020-26048
The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

NVD description · AI analysis pending
8.82%
  • cuppacms cuppacms
CVE-2018-19918
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

NVD description · AI analysis pending
5.4<1% PoC ×2
  • cuppacms cuppacms
CVE-2018-19559
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

NVD description · AI analysis pending
9.81% PoC
  • cuppacms cuppacms
CVE-2018-17300
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.

Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.

NVD description · AI analysis pending
4.8<1% PoC ×2
  • cuppacms cuppacms