Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Impresscms HIGH 8.8
CVE-2019-25703

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injec…

No fix yet
Fix from $1,950 2026-04-12
Impresscms CRITICAL 9.8
CVE-2022-50912

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A…

Mitigation only
Fix from $2,300 2026-01-13
Impresscms HIGH 7.2
CVE-2022-26986

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and …

Fix: after 1.4.3
Fix from $1,950 2022-04-05
Impresscms CRITICAL 9.8
CVE-2021-26599EPSS 21%

ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

Fix: 1.4.4+
Fix from $2,300 2022-03-28
Impresscms CRITICAL 9.8
CVE-2021-26600EPSS 6%

ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

Fix: 1.4.3+
Fix from $2,300 2022-03-28
Impresscms HIGH 8.1
CVE-2021-26601

ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

Fix: 1.4.3+
Fix from $1,950 2022-03-28
Impresscms MEDIUM 5.3
CVE-2021-26598EPSS 11%

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, ab…

Fix: 1.4.3+
Fix from $1,600 2022-03-28
Impresscms CRITICAL 9.8
CVE-2022-24977EPSS 6%

ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe int…

Fix: 1.4.2+
Fix from $2,300 2022-02-14
Impresscms MEDIUM 5.4
CVE-2021-28088

Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or…

No fix yet
Fix from $1,600 2021-03-11
Impresscms MEDIUM 6.1
CVE-2018-13983

ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

No fix yet
Fix from $1,600 2019-05-06
Impresscms MEDIUM 6.4
CVE-2014-1836

Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete ar…

Fix: after 1.3.5
Fix from $1,600 2015-07-01
Impresscms MEDIUM 6.0
CVE-2012-0987

Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated use…

Patch available
Fix from $1,600 2012-10-06
Impresscms HIGH 7.5
CVE-2010-4271

SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Fix: after 1.2.3
Fix from $1,950 2010-11-17
Impresscms MEDIUM 6.8
CVE-2008-5964

Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID paramete…

Fix: after 1.0.3
Fix from $1,600 2009-01-23
Impresscms HIGH 10.0
CVE-2008-3453

Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."

No fix yet
Fix from $1,950 2008-08-04