Greencms
Njtech · 11 CVEs
Green CMS 2.x Path Traversal Arbitrary File Download
Mar 21, 2026
Green CMS 2.x SQL Injection via cat Parameter
Mar 21, 2026
GreenCMS File DataController.class.php path traversal
Dec 29, 2025
GreenCMS Menu Management CustomController.class.php cross site scripting
Dec 8, 2025
GreenCMS index.php unrestricted upload
Aug 25, 2025
A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows att…
Jan 29, 2024
Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser functi…
Jun 20, 2023
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a…
Apr 26, 2022
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_…
Jun 20, 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.ph…
Jun 1, 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary…
Jun 1, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-25574 | Green CMS 2.x Path Traversal Arbitrary File Download | HIGH | 1.10% | Mar 21, 2026 |
| CVE-2019-25573 | Green CMS 2.x SQL Injection via cat Parameter | HIGH | 0.34% | Mar 21, 2026 |
| CVE-2025-15187 | GreenCMS File DataController.class.php path traversal | MEDIUM | 0.68% | Dec 29, 2025 |
| CVE-2025-14244 | GreenCMS Menu Management CustomController.class.php cross site scripting | MEDIUM | 0.27% | Dec 8, 2025 |
| CVE-2025-9415 | GreenCMS index.php unrestricted upload | MEDIUM | 0.35% | Aug 25, 2025 |
| CVE-2024-22570 | A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts… | MEDIUM | 0.28% | Jan 29, 2024 |
| CVE-2020-21366 | Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php. | HIGH | 0.33% | Jun 20, 2023 |
| CVE-2022-28918 | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=. | HIGH | 1.08% | Apr 26, 2022 |
| CVE-2018-12604 | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. | HIGH | 13.18% | Jun 20, 2018 |
| CVE-2018-11671 | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle. | HIGH | 2.48% | Jun 1, 2018 |
| CVE-2018-11670 | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to i… | HIGH | 2.48% | Jun 1, 2018 |
Showing 1 to 11 of 11 CVEs