Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
genixcms genixcms vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2017-14231
GeniXCMS prior to 1.1.0 allows remote malicious users to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class...
Genixcms Genixcms
7.3
CVSSv3
CVE-2016-10096
SQL injection vulnerability in register.php in GeniXCMS prior to 1.0.0 allows remote malicious users to execute arbitrary SQL commands via the activation parameter.
Genixcms Genixcms
NA
CVE-2015-2679
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS prior to 0.0.2 allow remote malicious users to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.
Genixcms Genixcms
1 EDB exploit
NA
CVE-2015-2678
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS prior to 0.0.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.
Genixcms Genixcms
1 EDB exploit
9.1
CVSSv3
CVE-2017-8827
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote malicious users to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.
Genixcms Genixcms 1.0.2
6.1
CVSSv3
CVE-2017-17431
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
Genixcms Genixcms 1.1.5
5.4
CVSSv3
CVE-2017-8376
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
Genixcms Genixcms 1.0.2
5.3
CVSSv3
CVE-2017-8388
GeniXCMS 1.0.2 allows remote malicious users to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
Genixcms Genixcms 1.0.2
5.4
CVSSv3
CVE-2017-8762
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
Genixcms Genixcms 1.0.2
4.8
CVSSv3
CVE-2017-8780
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.
Genixcms Genixcms 1.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »