Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
frog cms vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-20776
Frog CMS 0.9.5 provides a directory listing for a /public request.
Frog Cms Project Frog Cms 0.9.5
5.4
CVSSv3
CVE-2018-20777
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
Frog Cms Project Frog Cms 0.9.5
6.1
CVSSv3
CVE-2018-20778
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
Frog Cms Project Frog Cms 0.9.5
5.4
CVSSv3
CVE-2018-20448
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
Frog Cms Project Frog Cms 0.9.5
5.4
CVSSv3
CVE-2019-1010235
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.
Frog Cms Project Frog Cms 1.1
4.8
CVSSv3
CVE-2018-9991
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
Frog Cms Project Frog Cms 0.9.5
4.8
CVSSv3
CVE-2018-9992
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.
Frog Cms Project Frog Cms 0.9.5
8.8
CVSSv3
CVE-2018-8908
An issue exists in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges...
Frog Cms Project Frog Cms 0.9.5
1 EDB exploit
4.8
CVSSv3
CVE-2018-10321
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
Frogcms Project Frogcms 0.9.5
1 EDB exploit
8.8
CVSSv3
CVE-2018-16447
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
Frogcms Project Frogcms 0.9.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »