Vulnerabilities
43 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-25703 | ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL co ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2019-25575 | SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-50912 | ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server. NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — | |
| CVE-2025-52237 | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-45529 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET req An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2024-57099 +1 in the same advisory: …57097 | ClassCMS v4.8 has a code execution vulnerability. ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2024-12666 | A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-12503 | A vulnerability classified as problematic was found in ClassCMS 4.8. A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-48180 | ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-8144 +1 in the same advisory: …8145 | A vulnerability classified as problematic was found in ClassCMS 4.8. A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 group max | <1% | PoC |
| — | |
| CVE-2024-6932 | A vulnerability was found in ClassCMS 4.5. A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271987. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-31613 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-31609 | Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuratio Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2024-22938 | Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.c Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2023-43953 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-43952 +1 in the same advisory: …43951 | SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-37785 | A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-2862 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2022-44299 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. SiteServerCMS 7.1.3 sscms has a file read vulnerability. NVD description · AI analysis pending | 4.9 | <1% | PoC |
| — | |
| CVE-2022-44298 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. SiteServer CMS 7.1.3 is vulnerable to SQL Injection. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-44297 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-45966 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-44937 | Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2022-30349 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-42654 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2022-28606 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2022-28118 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2022-26986 | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system. NVD description · AI analysis pending | 7.2 | 4% | PoC |
| — | |
| CVE-2021-26599 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. NVD description · AI analysis pending | 9.8 group max | 21% | PoC ×3 |
| — | |
| CVE-2022-25582 | A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-25581 | Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2022-24977 | ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction wi ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress. NVD description · AI analysis pending | 9.8 | 6% | PoC |
| — | |
| CVE-2021-28088 | Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML param Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-17551 | ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. NVD description · AI analysis pending | 4.8 | 1% | PoC |
| — | |
| CVE-2018-13983 | ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php. ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php. NVD description · AI analysis pending | 6.1 | 2% | PoC ×2 |
| — |