Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cuppacms CRITICAL 9.8
CVE-2023-47990

SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via…

No fix yet
Fix from $2,300 2023-12-20
Cuppacms CRITICAL 9.8
CVE-2023-39681

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul…

No fix yet
Fix from $2,300 2023-09-05
Cuppacms HIGH 8.8
CVE-2022-37190EPSS 46%

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.p…

No fix yet
Fix from $1,950 2022-09-13
Cuppacms MEDIUM 6.5
CVE-2022-37191

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using…

No fix yet
Fix from $1,600 2022-09-13
Cuppacms CRITICAL 9.8
CVE-2022-38296

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

No fix yet
Fix from $2,300 2022-09-12
Cuppacms MEDIUM 6.1
CVE-2022-38295

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attack…

No fix yet
Fix from $1,600 2022-09-12
Cuppacms HIGH 7.5
CVE-2022-34121

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

No fix yet
Fix from $1,950 2022-07-27
Cuppacms CRITICAL 9.8
CVE-2022-27984EPSS 7%

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/…

Mitigation only
Fix from $2,300 2022-04-26
Cuppacms CRITICAL 9.8
CVE-2022-27985EPSS 7%

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

Mitigation only
Fix from $2,300 2022-04-26
Cuppacms CRITICAL 9.8
CVE-2022-25495

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c…

No fix yet
Fix from $2,300 2022-03-15
Cuppacms CRITICAL 9.8
CVE-2022-25498

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

No fix yet
Fix from $2,300 2022-03-15
Cuppacms HIGH 7.8
CVE-2022-25485EPSS 8%

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

No fix yet
Fix from $1,950 2022-03-15
Cuppacms HIGH 7.8
CVE-2022-25486EPSS 10%

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

No fix yet
Fix from $1,950 2022-03-15
Cuppacms MEDIUM 5.3
CVE-2022-25497

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

No fix yet
Fix from $1,600 2022-03-15
Cuppacms HIGH 7.5
CVE-2022-25401

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbi…

No fix yet
Fix from $1,950 2022-02-24
Cuppacms HIGH 8.1
CVE-2022-24647

Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

No fix yet
Fix from $1,950 2022-02-10
Cuppacms HIGH 7.5
CVE-2022-24264EPSS 7%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

No fix yet
Fix from $1,950 2022-01-31
Cuppacms HIGH 7.5
CVE-2022-24265EPSS 7%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 …

No fix yet
Fix from $1,950 2022-01-31
Cuppacms HIGH 7.5
CVE-2022-24266EPSS 6%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

Mitigation only
Fix from $1,950 2022-01-31
Cuppacms MEDIUM 5.4
CVE-2018-19918

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

No fix yet
Fix from $1,600 2018-12-31