Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-42970 | Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-3264 | SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2021-39599 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in admin.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-29250 +1 in the same advisory: …29249 | CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-35347 +1 in the same advisory: …35346 | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2020-28091 | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php. cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php. NVD description · AI analysis pending | 7.5 | 4% | PoC ×2 |
| — |