Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-30890 | Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. NVD description · AI analysis pending | 4.7 | <1% | PoC |
| — | |
| CVE-2022-28524 +1 in the same advisory: …28525 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2020-18261 | An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — |