Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
blackcat-cms blackcat cms vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2014-5259
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the msg parameter.
Blackcat-cms Blackcat Cms
5
CVSSv2
CVE-2015-5079
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS prior to 1.1.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the dl parameter.
Blackcat-cms Blackcat Cms
1 EDB exploit
6.8
CVSSv2
CVE-2020-25453
An issue exists in BlackCat CMS prior to 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Blackcat-cms Blackcat Cms
NA
CVE-2023-44042
A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.
Blackcat-cms Blackcat Cms 1.4.1
NA
CVE-2023-44043
A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.
Blackcat-cms Blackcat Cms 1.4.1
3.5
CVSSv2
CVE-2015-5521
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote malicious users to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.
Blackcat-cms Blackcat Cms 1.1.2
3.5
CVSSv2
CVE-2017-9609
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php.
Blackcat-cms Blackcat Cms 1.2
1 Github repository
6.5
CVSSv2
CVE-2017-14399
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
Blackcat-cms Blackcat Cms 1.2.2
3.5
CVSSv2
CVE-2018-10821
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.
Blackcat-cms Blackcat Cms 1.3
1 Github repository
6.5
CVSSv2
CVE-2017-14048
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.
Blackcat-cms Blackcat Cms 1.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »