Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
content management system vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and previous versions allows remote malicious users to delete arbitrary files via ".." sequences in the old_avatar parameter.
Exv2 Content Management System
1 EDB exploit
NA
CVE-2008-3154
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Webblizzard Content Management System
1 EDB exploit
6.1
CVSSv3
CVE-2023-48985
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
Cusg Content Management System
6.1
CVSSv3
CVE-2023-48986
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
Cusg Content Management System
7.5
CVSSv3
CVE-2023-48987
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
Cusg Content Management System
NA
CVE-2007-1966
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and previous versions allows remote malicious users to hijack web sessions by setting the PHPSESSID cookie.
Exv2 Content Management System 2.0.4.3
NA
CVE-2006-0466
Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote malicious users to inject arbitrary web script or HTML via the text parameter.
Goldstag Goldstag Content Management System
NA
CVE-2015-4427
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) prior to 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page, (2) action, (3) folder_...
Ektron Ektron Content Management System
NA
CVE-2007-1907
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote malicious users to execute arbitrary PHP code via a URL in the file parameter.
Pathos Content Management System 0.92.2
1 EDB exploit
6.1
CVSSv3
CVE-2016-6133
Cross-site scripting (XSS) vulnerability in Ektron Content Management System prior to 9.1.0.184SP3(9.1.0.184.3.127) allows remote malicious users to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.aspx.
Ektron Ektron Content Management System
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-17519
open redirect
CVE-2024-21683
cache poisoning
CVE-2021-47524
CVE-2021-47521
CVE-2024-5229
CVE-2021-47560
local
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »