CVE Browser

More filters (active)
CVE-2021-43736 CRITICAL

CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule

CVSS 9.8 EPSS 2.48% Mar 23, 2022
CVE-2021-43735 CRITICAL

CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.

CVSS 9.8 EPSS 1.26% Mar 23, 2022
CVE-2020-24993 MEDIUM

There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.

CVSS 5.4 EPSS 0.50% May 17, 2021
CVE-2020-24992 MEDIUM

There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content managem…

CVSS 5.4 EPSS 0.51% May 17, 2021
CVE-2020-20296 CRITICAL

An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute…

CVSS 9.8 EPSS 1.35% Feb 1, 2021
CVE-2020-20295 CRITICAL

An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute ar…

CVSS 9.8 EPSS 1.35% Feb 1, 2021
CVE-2020-20294 CRITICAL

An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary comm…

CVSS 9.8 EPSS 1.77% Feb 1, 2021
CVE-2019-7649 HIGH

global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.

CVSS 7.5 EPSS 0.89% Feb 17, 2019

Showing 1 to 8 CVEs · page 1