Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cuppacms cuppacms 1.0 vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv2
CVE-2022-24647
Cuppa CMS v1.0 exists to contain an arbitrary file deletion vulnerability via the unlink() function.
Cuppacms Cuppacms 1.0
NA
CVE-2022-38295
Cuppa CMS v1.0 exists to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.
Cuppacms Cuppacms 1.0
NA
CVE-2022-38296
Cuppa CMS v1.0 exists to contain an arbitrary file upload vulnerability via the File Manager.
Cuppacms Cuppacms 1.0
7.8
CVSSv2
CVE-2022-24265
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
Cuppacms Cuppacms 1.0
NA
CVE-2022-34121
Cuppa CMS v1.0 exists to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
Cuppacms Cuppacms 1.0
NA
CVE-2023-47990
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows malicious users to run arbitrary SQL commands via the table parameter.
Cuppacms Cuppacms 1.0
7.5
CVSSv2
CVE-2022-27985
CuppaCMS v1.0 exists to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Cuppacms Cuppacms 1.0
7.8
CVSSv2
CVE-2022-24264
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
Cuppacms Cuppacms 1.0
7.8
CVSSv2
CVE-2022-24266
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
Cuppacms Cuppacms 1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2