Lucene search

K

Cmswing Security Vulnerabilities

cve
cve

CVE-2021-43735

CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior...

9.8CVSS

9.4AI Score

0.002EPSS

2022-03-23 04:15 PM
59
cve
cve

CVE-2021-43736

CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log...

9.8CVSS

9.7AI Score

0.006EPSS

2022-03-23 04:15 PM
69
cve
cve

CVE-2020-24992

There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management...

5.4CVSS

5.3AI Score

0.001EPSS

2021-05-17 07:15 PM
17
2
cve
cve

CVE-2020-24993

There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article...

5.4CVSS

5.3AI Score

0.001EPSS

2021-05-17 07:15 PM
18
cve
cve

CVE-2020-20294

An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary...

9.8CVSS

9.6AI Score

0.004EPSS

2021-02-01 06:15 PM
16
cve
cve

CVE-2020-20295

An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL...

9.8CVSS

9.8AI Score

0.004EPSS

2021-02-01 06:15 PM
25
cve
cve

CVE-2020-20296

An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL...

9.8CVSS

9.8AI Score

0.004EPSS

2021-02-01 06:15 PM
26
cve
cve

CVE-2019-7649

global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password...

7.5CVSS

7.6AI Score

0.004EPSS

2019-02-17 09:29 PM
29