|
209001
|
4.8 |
MEDIUM
Network
|
ecisp
|
espcms
|
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18404
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209002
|
6.8 |
MEDIUM
Network
|
jyuu
|
jymusic
|
An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment informatio…
|
CWE-352
Origin Validation Error
|
CVE-2020-18416
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209003
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18413
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209004
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18410
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209005
|
7.5 |
HIGH
Network
|
cmseasy
|
cmseasy
|
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-18406
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209006
|
8.8 |
HIGH
Network
|
feifeicms
|
feifeicms
|
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
|
CWE-352
Origin Validation Error
|
CVE-2020-18418
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209007
|
7.5 |
HIGH
Network
|
emlog
|
emlog
|
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19028
|
2024-11-21 14:08 |
2023-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209008
|
6.1 |
MEDIUM
Network
|
md_project
|
md
|
Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a local attacker to execute arbitrary code via the EMBED SRC function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18280
|
2024-11-21 14:08 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209009
|
6.1 |
MEDIUM
Network
|
5none
|
nonecms
|
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18282
|
2024-11-21 14:08 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209010
|
4.8 |
MEDIUM
Network
|
mipcms
|
mipcms
|
Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category name field to categoryEdit.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18132
|
2024-11-21 14:08 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|