CVE Browser

More filters (active)
CVE-2025-12920 MEDIUM

qianfox FoxCMS Product.php edit cross site scripting

CVSS 4.8 EPSS 0.33% Nov 9, 2025
CVE-2025-10251 MEDIUM

FoxCMS Images.php batchCope sql injection

CVSS 5.3 EPSS 0.37% Sep 11, 2025
CVE-2025-56630 HIGH

FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

CVSS 7.3 EPSS 0.21% Sep 8, 2025
CVE-2025-56435 MEDIUM

SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on t…

CVSS 5.3 EPSS 0.35% Sep 3, 2025
CVE-2025-55422 HIGH

In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

CVSS 8.8 EPSS 0.41% Aug 27, 2025
CVE-2025-55409 HIGH

FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.

CVSS 8.8 EPSS 0.49% Aug 25, 2025
CVE-2025-55420 HIGH

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected…

CVSS 8.8 EPSS 0.49% Aug 21, 2025
CVE-2025-50692 CRITICAL

FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

CVSS 9.8 EPSS 0.65% Aug 7, 2025
CVE-2025-46154 HIGH

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

CVSS 8.4 EPSS 0.22% Jun 3, 2025
CVE-2025-5155 MEDIUM

qianfox FoxCMS Article.php batchCope sql injection

CVSS 5.3 EPSS 0.49% May 25, 2025
CVE-2025-29181 HIGH

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

CVSS 7.2 EPSS 0.39% Apr 17, 2025
CVE-2025-29180 HIGH

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are direc…

CVSS 7.2 EPSS 0.39% Apr 17, 2025
CVE-2025-29306 CRITICAL

An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

CVSS 9.8 EPSS 46.58% Mar 27, 2025
CVE-2025-25790 CRITICAL

An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading…

CVSS 9.8 EPSS 0.91% Feb 26, 2025
CVE-2025-25789 CRITICAL

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

CVSS 9.8 EPSS 1.31% Feb 26, 2025

Showing 1 to 15 CVEs · page 1