ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-3464
A vulnerability classified as problematic has been found in puppyCMS up to 5.1.

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

NVD description · AI analysis pending
6.1<1%
  • puppycms puppycms
CVE-2020-18890
+2 in the same advisory: …18888 …18889
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php

Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • puppycms puppycms
CVE-2018-15847
An issue was discovered in puppyCMS 5.1.

An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.

NVD description · AI analysis pending
6.1<1%
  • puppycms puppycms