Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icms vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-11426
An XSS issue exists in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.
Idreamsoft Icms 7.0.14
6.1
CVSSv3
CVE-2019-11427
An XSS issue exists in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.
Idreamsoft Icms 7.0.14
8.8
CVSSv3
CVE-2020-26641
A Cross Site Request Forgery (CSRF) vulnerability exists in iCMS 7.0.16 which can allow an malicious user to execute arbitrary web scripts.
Idreamsoft Icms 7.0.16
9.8
CVSSv3
CVE-2019-17552
An issue exists in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
Idreamsoft Icms 7.0.14
7.5
CVSSv3
CVE-2019-17583
idreamsoft iCMS 7.0.15 allows remote malicious users to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
Idreamsoft Icms 7.0.15
8.8
CVSSv3
CVE-2018-10222
An issue exists in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.
Icmsdev Icms 7.0
5.4
CVSSv3
CVE-2018-10250
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.
Icmsdev Icms 7.0.8
9.8
CVSSv3
CVE-2023-39805
iCMS v7.0.16 exists to contain a SQL injection vulnerability via the where parameter at admincp.php.
Idreamsoft Icms 7.0.16
9.8
CVSSv3
CVE-2023-39806
iCMS v7.0.16 exists to contain a SQL injection vulnerability via the bakupdata function.
Idreamsoft Icms 7.0.16
9.8
CVSSv3
CVE-2022-41496
iCMS v7.0.16 exists to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
Idreamsoft Icms 7.0.16
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »