Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
content management system vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2007-1949
Session fixation vulnerability in WebBlizzard CMS allows remote malicious users to hijack web sessions by setting a PHPSESSID cookie.
Webblizzard Content Management System
383
VMScore
CVE-2007-1950
Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote malicious users to inject arbitrary web script or HTML via the Suchzeile parameter.
Webblizzard Content Management System
383
VMScore
CVE-2007-1965
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.
Exv2 Content Management System
312
VMScore
CVE-2022-26565
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.
Totaljs Content Management System
755
VMScore
CVE-2008-3154
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Webblizzard Content Management System
1 EDB exploit
755
VMScore
CVE-2012-5357
Ektron Content Management System (CMS) prior to 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote malicious users to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.
Ektron Ektron Content Management System
1 EDB exploit
668
VMScore
CVE-2012-5358
The XSLTCompiledTransform function in Ektron Content Management System (CMS) prior to 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote malicious users to read arbitrary files and consequently bypass authentication, modify viewstate, cause a...
Ektron Ektron Content Management System
685
VMScore
CVE-2007-1907
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote malicious users to execute arbitrary PHP code via a URL in the file parameter.
Pathos Content Management System 0.92.2
1 EDB exploit
383
VMScore
CVE-2016-6133
Cross-site scripting (XSS) vulnerability in Ektron Content Management System prior to 9.1.0.184SP3(9.1.0.184.3.127) allows remote malicious users to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.aspx.
Ektron Ektron Content Management System
383
VMScore
CVE-2016-6201
Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) prior to 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote malicious users to inject arbitrary web script or HTML via the ContType parameter in a ViewContentByCategory action to WorkArea/content.aspx.
Ektron Ektron Content Management System
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »