ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26268
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

NVD description · AI analysis pending
9.8<1% PoC
  • xiaohuanxiong project xiaohuanxiong
CVE-2021-43737
An issus was discovered in xiaohuanxiong CMS 5.0.17.

An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.

NVD description · AI analysis pending
6.5<1% PoC
  • xiaohuanxiong project xiaohuanxiong cms