Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
blackcat-cms blackcat cms vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2014-5259
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the msg parameter.
Blackcat-cms Blackcat Cms
6.8
CVSSv2
CVE-2020-25453
An issue exists in BlackCat CMS prior to 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Blackcat-cms Blackcat Cms
5
CVSSv2
CVE-2015-5079
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS prior to 1.1.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the dl parameter.
Blackcat-cms Blackcat Cms
1 EDB exploit
NA
CVE-2023-44042
A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.
Blackcat-cms Blackcat Cms 1.4.1
NA
CVE-2023-44043
A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.
Blackcat-cms Blackcat Cms 1.4.1
3.5
CVSSv2
CVE-2020-25878
A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated malicious users to execute arbitrary web scripts or HTML via crafted payloads entered into the 'Output Filters' and 'Droplets' m...
Blackcat-cms Blackcat Cms 1.3.6
3.5
CVSSv2
CVE-2021-27237
The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.
Blackcat-cms Blackcat Cms 1.3.6
3.5
CVSSv2
CVE-2015-5521
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote malicious users to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.
Blackcat-cms Blackcat Cms 1.1.2
3.5
CVSSv2
CVE-2020-25877
A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated malicious users to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
Blackcat-cms Blackcat Cms 1.3.6
3.5
CVSSv2
CVE-2017-9609
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php.
Blackcat-cms Blackcat Cms 1.2
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »