Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cuppacms cuppacms 1.0 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2022-25401
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
Cuppacms Cuppacms 1.0
6.8
CVSSv2
CVE-2022-25485
CuppaCMS v1.0 exists to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
Cuppacms Cuppacms 1.0
6.8
CVSSv2
CVE-2022-25486
CuppaCMS v1.0 exists to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
Cuppacms Cuppacms 1.0
7.5
CVSSv2
CVE-2022-25495
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows malicious users to upload arbitrary files and execute arbitrary code via a crafted PHP file.
Cuppacms Cuppacms 1.0
5
CVSSv2
CVE-2022-25497
CuppaCMS v1.0 exists to contain an arbitrary file read via the copy function.
Cuppacms Cuppacms 1.0
7.5
CVSSv2
CVE-2022-25498
CuppaCMS v1.0 exists to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
Cuppacms Cuppacms 1.0
NA
CVE-2022-37190
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
Cuppacms Cuppacms 1.0
NA
CVE-2022-37191
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
Cuppacms Cuppacms 1.0
NA
CVE-2022-34121
Cuppa CMS v1.0 exists to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
Cuppacms Cuppacms 1.0
7.8
CVSSv2
CVE-2022-24264
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
Cuppacms Cuppacms 1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »