Wolfcms / Wolf Cms
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-25070 | WolfCMS User Add cross site scripting | MEDIUM | 6.1 | Jun 9, 2022 |
| CVE-2012-1932 | A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_em… | MEDIUM | 4.8 | Feb 19, 2020 |
| CVE-2018-18824 | WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | MEDIUM | 4.8 | Apr 25, 2019 |
| CVE-2018-18823 | WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | MEDIUM | 4.8 | Apr 25, 2019 |
| CVE-2019-10646 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaS… | MEDIUM | 6.1 | Mar 30, 2019 |
| CVE-2018-15842 | WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. | MEDIUM | 4.8 | Aug 25, 2018 |
| CVE-2018-14837 | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. | MEDIUM | 4.8 | Aug 10, 2018 |
| CVE-2018-8814 | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugi… | MEDIUM | 6.5 | Apr 4, 2018 |
| CVE-2018-8813 | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web… | MEDIUM | 4.8 | Apr 4, 2018 |
| CVE-2018-1000087 | WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files'… | MEDIUM | 4.8 | Mar 13, 2018 |
| CVE-2018-1000084 | WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege… | MEDIUM | 5.4 | Mar 13, 2018 |
| CVE-2018-6890 | Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3. | MEDIUM | 4.8 | Feb 22, 2018 |
| CVE-2017-11611 | Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup"… | MEDIUM | 5.4 | Sep 8, 2017 |
| CVE-2015-6568 | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent… | HIGH | 8.8 | Apr 14, 2017 |
| CVE-2015-6567 | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validat… | HIGH | 8.8 | Apr 14, 2017 |
| CVE-2012-1897 | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators f… | MEDIUM | 6.8 | Oct 1, 2012 |
Showing 1 to 16 of 16 CVEs