|
209131
|
5.4 |
MEDIUM
Network
|
ukcms
|
ukcms
|
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-18449
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209132
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18446
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209133
|
6.1 |
MEDIUM
Network
|
yunucms
|
yunucms
|
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18445
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209134
|
8.8 |
HIGH
Network
|
ignitedcms
|
ignitedcms
|
Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile".
|
CWE-352
Origin Validation Error
|
CVE-2020-18694
|
2024-11-21 14:08 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209135
|
5.4 |
MEDIUM
Network
|
mineweb
|
minewebcms
|
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18693
|
2024-11-21 14:08 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209136
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19118
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209137
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
|
CWE-89
SQL Injection
|
CVE-2020-18175
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209138
|
5.4 |
MEDIUM
Network
|
hucart
|
hucart
|
Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18158
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209139
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-18157
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209140
|
9.8 |
CRITICAL
Network
|
whatsns
|
whatsns
|
SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.
|
CWE-89
SQL Injection
|
CVE-2020-18013
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|