5none / Nonecms
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-18282 | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. | MEDIUM | 6.1 | May 8, 2023 |
| CVE-2020-18647 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor". | HIGH | 7.5 | Jun 22, 2021 |
| CVE-2020-18646 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php". | HIGH | 7.5 | Jun 22, 2021 |
| CVE-2020-23371 | Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inj… | MEDIUM | 6.1 | May 10, 2021 |
| CVE-2020-23373 | Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML v… | MEDIUM | 5.4 | May 10, 2021 |
| CVE-2020-23374 | Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HT… | MEDIUM | 5.4 | May 10, 2021 |
| CVE-2020-23376 | NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrar… | MEDIUM | 6.1 | May 10, 2021 |
| CVE-2019-16721 | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. | MEDIUM | 6.5 | Sep 23, 2019 |
| CVE-2018-20062 KEV | An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter par… | CRITICAL | 9.8 | Dec 11, 2018 |
| CVE-2018-7219 | application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/adm… | HIGH | 8.8 | Feb 19, 2018 |
| CVE-2018-6029 | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network r… | HIGH | 7.5 | Jan 23, 2018 |
| CVE-2018-6022 | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files… | MEDIUM | 6.5 | Jan 23, 2018 |
Showing 1 to 12 of 12 CVEs