Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
content management system vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2005-2488
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote malicious users to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
Web Content Management Web Content Management News System
2 EDB exploits
7.5
CVSSv2
CVE-2005-2489
Web Content Management News System allows remote malicious users to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.
Web Content Management Web Content Management News System
3.5
CVSSv2
CVE-2020-36498
Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field.
Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System 1.14f
NA
CVE-2023-48985
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
Cusg Content Management System
NA
CVE-2023-48986
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
Cusg Content Management System
NA
CVE-2023-48987
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
Cusg Content Management System
4.3
CVSSv2
CVE-2007-4365
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
Exv2 Content Management System
7.5
CVSSv2
CVE-2006-5030
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.
Exv2 Content Management System
1 EDB exploit
7.5
CVSSv2
CVE-2008-3154
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Webblizzard Content Management System
1 EDB exploit
4.3
CVSSv2
CVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and previous versions allows remote malicious users to delete arbitrary files via ".." sequences in the old_avatar parameter.
Exv2 Content Management System
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-34377
CVE-2024-20859
CVE-2023-49606
inject
arbitrary
CVE-2024-33788
CVE-2024-30973
IDOR
CVE-2024-33907
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »