Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Cmsuno
CRITICAL 9.8
CVE-2021-40889
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents…
No fix yet
Fix from $2,300
2021-10-11
Cmsuno
MEDIUM 5.4
CVE-2021-36654
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.
No fix yet
Fix from $1,600
2021-08-03
Cmsuno
HIGH 8.8
CVE-2020-25538EPSS 10%
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web p…
No fix yet
Fix from $1,950
2020-11-13
Cmsuno
HIGH 8.8
CVE-2020-25557EPSS 10%
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs…
No fix yet
Fix from $1,950
2020-11-13
Cmsuno
MEDIUM 6.5
CVE-2020-15600
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
Fix: 1.6.1+
Fix from $1,600
2020-07-07
Cmsuno
MEDIUM 6.1
CVE-2018-15567
CMSUno before 1.5.3 has XSS via the title field.
Fix: 1.5.3+
Fix from $1,600
2018-08-20