Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2025-70073
An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function
Chestnutcms
after 1.5.8
HIGH 8.8
CVE-2025-15009
A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com…
Chestnutcms
after 1.5.8
HIGH 8.8
CVE-2025-5552
A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/g…
Chestnutcms
No fix yet
HIGH 7.5
CVE-2025-2917
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cm…
Chestnutcms
after 1.5.3
HIGH 7.6
CVE-2025-2031
A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/…
Chestnutcms
No fix yet
HIGH 7.5
CVE-2024-57451
ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any …
Chestnutcms
after 1.5.0
CRITICAL 9.8
CVE-2024-57450
ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
Chestnutcms
after 1.5.0
HIGH 7.5
CVE-2024-57452
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file …
Chestnutcms
after 1.5.0
CRITICAL 9.8
CVE-2024-56828
File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receiv…
Chestnutcms
after 1.5.0