Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nonecms MEDIUM 6.1
CVE-2020-18282

Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.

No fix yet
Fix from $1,600 2023-05-08
Nonecms HIGH 7.5
CVE-2020-18647

Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

No fix yet
Fix from $1,950 2021-06-22
Nonecms HIGH 7.5
CVE-2020-18646

Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

No fix yet
Fix from $1,950 2021-06-22
Nonecms MEDIUM 6.1
CVE-2020-23371

Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attack…

No fix yet
Fix from $1,600 2021-05-10
Nonecms MEDIUM 6.1
CVE-2020-23376

NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected wit…

No fix yet
Fix from $1,600 2021-05-10
Nonecms MEDIUM 5.4
CVE-2020-23373

Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script…

No fix yet
Fix from $1,600 2021-05-10
Nonecms MEDIUM 5.4
CVE-2020-23374

Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web sc…

No fix yet
Fix from $1,600 2021-05-10
Nonecms MEDIUM 6.5
CVE-2019-16721

NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.

No fix yet
Fix from $1,600 2019-09-23
Nonecms CRITICAL 9.8
CVE-2018-20062 KEVEPSS 100%

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the …

Mitigation only
Fix from $2,300 2018-12-11
Nonecms HIGH 8.8
CVE-2018-7219

application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/ind…

No fix yet
Fix from $1,950 2018-02-19
Nonecms HIGH 7.5
CVE-2018-6029

The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external…

No fix yet
Fix from $1,950 2018-01-23