Monocms
Monocms · 6 CVEs
CVE-2024-10928
MEDIUM
MonoCMS Posts Page opensaved.php cross site scripting
Nov 6, 2024
CVE-2024-10927
MEDIUM
MonoCMS Account Information Page account.php cross site scripting
Nov 6, 2024
CVE-2020-28672
HIGH
MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles…
Jan 7, 2021
CVE-2020-25985
HIGH
MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webser…
Oct 7, 2020
CVE-2020-25986
MEDIUM
A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
Oct 6, 2020
CVE-2020-25987
HIGH
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is…
Oct 6, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-10928 | MonoCMS Posts Page opensaved.php cross site scripting | MEDIUM | 0.39% | Nov 6, 2024 |
| CVE-2024-10927 | MonoCMS Account Information Page account.php cross site scripting | MEDIUM | 0.42% | Nov 6, 2024 |
| CVE-2020-28672 | MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be save… | HIGH | 12.14% | Jan 7, 2021 |
| CVE-2020-25985 | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not d… | HIGH | 1.72% | Oct 7, 2020 |
| CVE-2020-25986 | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. | MEDIUM | 0.57% | Oct 6, 2020 |
| CVE-2020-25987 | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used… | HIGH | 1.63% | Oct 6, 2020 |
Showing 1 to 6 of 6 CVEs