Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
idreamsoft icms vulnerabilities and exploits
(subscribe to this query)
436
VMScore
CVE-2019-8902
An issue exists in idreamsoft iCMS up to and including 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Idreamsoft Icms
445
VMScore
CVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an malicious user to read arbitrary files.
Idreamsoft Icms
668
VMScore
CVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Idreamsoft Icms
570
VMScore
CVE-2020-18070
Path Traversal in iCMS v7.0.13 allows remote malicious users to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
Idreamsoft Icms 7.0.13
NA
CVE-2023-39806
iCMS v7.0.16 exists to contain a SQL injection vulnerability via the bakupdata function.
Idreamsoft Icms 7.0.16
578
VMScore
CVE-2018-16320
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
Idreamsoft Icms 7.0.11
605
VMScore
CVE-2020-26641
A Cross Site Request Forgery (CSRF) vulnerability exists in iCMS 7.0.16 which can allow an malicious user to execute arbitrary web scripts.
Idreamsoft Icms 7.0.16
NA
CVE-2023-39805
iCMS v7.0.16 exists to contain a SQL injection vulnerability via the where parameter at admincp.php.
Idreamsoft Icms 7.0.16
383
VMScore
CVE-2019-11427
An XSS issue exists in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.
Idreamsoft Icms 7.0.14
890
VMScore
CVE-2020-19142
iCMS 7 malicious users to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
Idreamsoft Icms 7.0.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »