Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-47990 SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via… Cuppacms No fix yet Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-39681 Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul… Cuppacms No fix yet Fix from $2,3002023-09-05 HIGH 8.8 CVE-2022-37190EPSS 46% CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.p… Cuppacms No fix yet Fix from $1,9502022-09-13 MEDIUM 6.5 CVE-2022-37191 The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using… Cuppacms No fix yet Fix from $1,6002022-09-13 CRITICAL 9.8 CVE-2022-38296 Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. Cuppacms No fix yet Fix from $2,3002022-09-12 MEDIUM 6.1 CVE-2022-38295 Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attack… Cuppacms No fix yet Fix from $1,6002022-09-12 HIGH 7.5 CVE-2022-34121 Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php. Cuppacms No fix yet Fix from $1,9502022-07-27 CRITICAL 9.8 CVE-2022-27984EPSS 7% CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/… Cuppacms Mitigation only Fix from $2,3002022-04-26 CRITICAL 9.8 CVE-2022-27985EPSS 7% CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. Cuppacms Mitigation only Fix from $2,3002022-04-26 CRITICAL 9.8 CVE-2022-25495 The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c… Cuppacms No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-25498 CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php. Cuppacms No fix yet Fix from $2,3002022-03-15 HIGH 7.8 CVE-2022-25485EPSS 8% CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. Cuppacms No fix yet Fix from $1,9502022-03-15 HIGH 7.8 CVE-2022-25486EPSS 10% CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. Cuppacms No fix yet Fix from $1,9502022-03-15 MEDIUM 5.3 CVE-2022-25497 CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. Cuppacms No fix yet Fix from $1,6002022-03-15 HIGH 7.5 CVE-2022-25401 The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbi… Cuppacms No fix yet Fix from $1,9502022-02-24 HIGH 8.1 CVE-2022-24647 Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function. Cuppacms No fix yet Fix from $1,9502022-02-10 HIGH 7.5 CVE-2022-24264EPSS 7% Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter. Cuppacms No fix yet Fix from $1,9502022-01-31 HIGH 7.5 CVE-2022-24265EPSS 7% Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 … Cuppacms No fix yet Fix from $1,9502022-01-31 HIGH 7.5 CVE-2022-24266EPSS 6% Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter. Cuppacms Mitigation only Fix from $1,9502022-01-31 MEDIUM 5.4 CVE-2018-19918 CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI. Cuppacms No fix yet Fix from $1,6002018-12-31