Horizontcms
Horizontcms Project · 4 CVEs
CVE-2021-28428
CRITICAL
File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Medi…
Apr 5, 2022
CVE-2022-25104
HIGH
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/f…
Feb 23, 2022
CVE-2020-28693
HIGH
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code…
Nov 16, 2020
CVE-2020-27387
HIGH
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with acces…
Nov 5, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-28428 | File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The origin… | CRITICAL | 1.24% | Apr 5, 2022 |
| CVE-2022-25104 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/. | HIGH | 1.14% | Feb 23, 2022 |
| CVE-2020-28693 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme,… | HIGH | 2.53% | Nov 16, 2020 |
| CVE-2020-27387 | An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and exec… | HIGH | 18.46% | Nov 5, 2020 |
Showing 1 to 4 of 4 CVEs