Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
blackcat-cms blackcat cms vulnerabilities and exploits
(subscribe to this query)
505
VMScore
CVE-2015-5079
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS prior to 1.1.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the dl parameter.
Blackcat-cms Blackcat Cms
1 EDB exploit
383
VMScore
CVE-2014-5259
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the msg parameter.
Blackcat-cms Blackcat Cms
605
VMScore
CVE-2020-25453
An issue exists in BlackCat CMS prior to 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Blackcat-cms Blackcat Cms
NA
CVE-2023-44042
A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.
Blackcat-cms Blackcat Cms 1.4.1
NA
CVE-2023-44043
A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.
Blackcat-cms Blackcat Cms 1.4.1
312
VMScore
CVE-2018-10821
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.
Blackcat-cms Blackcat Cms 1.3
1 Github repository
312
VMScore
CVE-2015-5521
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote malicious users to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.
Blackcat-cms Blackcat Cms 1.1.2
312
VMScore
CVE-2020-25878
A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated malicious users to execute arbitrary web scripts or HTML via crafted payloads entered into the 'Output Filters' and 'Droplets' m...
Blackcat-cms Blackcat Cms 1.3.6
312
VMScore
CVE-2018-16635
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
Blackcat-cms Blackcat Cms 1.3.2
356
VMScore
CVE-2017-13670
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.
Blackcat-cms Blackcat Cms 1.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29824
CVE-2024-30095
CVE-2024-30104
client side
CVE-2024-5840
CVE-2024-34405
unprivileged
wireless
CVE-2024-4577
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »