Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-18282 Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. Nonecms No fix yet Fix from $1,6002023-05-08 HIGH 7.5 CVE-2020-18647 Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor". Nonecms No fix yet Fix from $1,9502021-06-22 HIGH 7.5 CVE-2020-18646 Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php". Nonecms No fix yet Fix from $1,9502021-06-22 MEDIUM 6.1 CVE-2020-23371 Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attack… Nonecms No fix yet Fix from $1,6002021-05-10 MEDIUM 6.1 CVE-2020-23376 NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected wit… Nonecms No fix yet Fix from $1,6002021-05-10 MEDIUM 5.4 CVE-2020-23373 Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script… Nonecms No fix yet Fix from $1,6002021-05-10 MEDIUM 5.4 CVE-2020-23374 Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web sc… Nonecms No fix yet Fix from $1,6002021-05-10 MEDIUM 6.5 CVE-2019-16721 NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. Nonecms No fix yet Fix from $1,6002019-09-23 CRITICAL 9.8 CVE-2018-20062 KEVEPSS 100% An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the … Nonecms Mitigation only Fix from $2,3002018-12-11 HIGH 8.8 CVE-2018-7219 application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/ind… Nonecms No fix yet Fix from $1,9502018-02-19 HIGH 7.5 CVE-2018-6029 The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external… Nonecms No fix yet Fix from $1,9502018-01-23 MEDIUM 6.5 CVE-2018-6022 Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbit… Nonecms after 1.3.0 Fix from $1,6002018-01-23