Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cuppacms cuppacms 1.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-38296
Cuppa CMS v1.0 exists to contain an arbitrary file upload vulnerability via the File Manager.
Cuppacms Cuppacms 1.0
668
VMScore
CVE-2022-27985
CuppaCMS v1.0 exists to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Cuppacms Cuppacms 1.0
NA
CVE-2022-37190
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
Cuppacms Cuppacms 1.0
NA
CVE-2022-37191
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.
Cuppacms Cuppacms 1.0
490
VMScore
CVE-2022-24647
Cuppa CMS v1.0 exists to contain an arbitrary file deletion vulnerability via the unlink() function.
Cuppacms Cuppacms 1.0
NA
CVE-2022-34121
Cuppa CMS v1.0 exists to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
Cuppacms Cuppacms 1.0
NA
CVE-2022-38295
Cuppa CMS v1.0 exists to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.
Cuppacms Cuppacms 1.0
668
VMScore
CVE-2022-27984
CuppaCMS v1.0 exists to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Cuppacms Cuppacms 1.0
694
VMScore
CVE-2022-24264
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
Cuppacms Cuppacms 1.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2