Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-25703
ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injec…
Impresscms
No fix yet
CRITICAL 9.8
CVE-2022-50912
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A…
Impresscms
Mitigation only
HIGH 7.2
CVE-2022-26986
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and …
Impresscms
after 1.4.3
CRITICAL 9.8
CVE-2021-26599EPSS 21%
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
Impresscms
1.4.4+
CRITICAL 9.8
CVE-2021-26600EPSS 6%
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
Impresscms
1.4.3+
HIGH 8.1
CVE-2021-26601
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
Impresscms
1.4.3+
MEDIUM 5.3
CVE-2021-26598EPSS 11%
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, ab…
Impresscms
1.4.3+
CRITICAL 9.8
CVE-2022-24977EPSS 6%
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe int…
Impresscms
1.4.2+
MEDIUM 5.4
CVE-2021-28088
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or…
Impresscms
No fix yet
MEDIUM 6.1
CVE-2018-13983
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.
Impresscms
No fix yet
MEDIUM 6.4
CVE-2014-1836
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete ar…
Impresscms
after 1.3.5
MEDIUM 6.0
CVE-2012-0987
Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated use…
Impresscms
Patch available
HIGH 7.5
CVE-2010-4271
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Impresscms
after 1.2.3
MEDIUM 6.8
CVE-2008-5964
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID paramete…
Impresscms
after 1.0.3
HIGH 10.0
CVE-2008-3453
Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."
Impresscms
No fix yet