Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-53892 Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jq… Blackcat Cms No fix yet Fix from $1,9502025-12-15 MEDIUM 5.4 CVE-2023-53891 Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. … Blackcat Cms No fix yet Fix from $1,6002025-12-15 MEDIUM 6.1 CVE-2023-44043 A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts o… Blackcat Cms No fix yet Fix from $1,6002023-09-27 MEDIUM 5.4 CVE-2023-44042 A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or … Blackcat Cms No fix yet Fix from $1,6002023-09-27 MEDIUM 5.4 CVE-2020-25877 A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary… Blackcat Cms No fix yet Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2018-16635 Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. Blackcat Cms No fix yet Fix from $1,6002018-12-10 HIGH 8.8 CVE-2017-14399 In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing… Blackcat Cms Mitigation only Fix from $1,9502017-09-12 HIGH 8.8 CVE-2017-14048 BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addon… Blackcat Cms Mitigation only Fix from $1,9502017-08-31 HIGH 8.8 CVE-2017-14050 In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .ph… Blackcat Cms Mitigation only Fix from $1,9502017-08-31 MEDIUM 6.5 CVE-2017-13670 In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated b… Blackcat Cms No fix yet Fix from $1,6002017-08-31 MEDIUM 5.4 CVE-2017-14049 In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Websi… Blackcat Cms Mitigation only Fix from $1,6002017-08-31