Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-25703 ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injec… Impresscms No fix yet Fix from $1,9502026-04-12 CRITICAL 9.8 CVE-2022-50912 ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A… Impresscms Mitigation only Fix from $2,3002026-01-13 HIGH 7.2 CVE-2022-26986 SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and … Impresscms after 1.4.3 Fix from $1,9502022-04-05 CRITICAL 9.8 CVE-2021-26599EPSS 21% ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. Impresscms 1.4.4+ Fix from $2,3002022-03-28 CRITICAL 9.8 CVE-2021-26600EPSS 6% ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). Impresscms 1.4.3+ Fix from $2,3002022-03-28 HIGH 8.1 CVE-2021-26601 ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. Impresscms 1.4.3+ Fix from $1,9502022-03-28 MEDIUM 5.3 CVE-2021-26598EPSS 11% ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, ab… Impresscms 1.4.3+ Fix from $1,6002022-03-28 CRITICAL 9.8 CVE-2022-24977EPSS 6% ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe int… Impresscms 1.4.2+ Fix from $2,3002022-02-14 MEDIUM 5.4 CVE-2021-28088 Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or… Impresscms No fix yet Fix from $1,6002021-03-11 MEDIUM 6.1 CVE-2018-13983 ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php. Impresscms No fix yet Fix from $1,6002019-05-06 MEDIUM 6.4 CVE-2014-1836 Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete ar… Impresscms after 1.3.5 Fix from $1,6002015-07-01 MEDIUM 6.0 CVE-2012-0987 Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated use… Impresscms Patch available Fix from $1,6002012-10-06 HIGH 7.5 CVE-2010-4271 SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Impresscms after 1.2.3 Fix from $1,9502010-11-17 MEDIUM 6.8 CVE-2008-5964 Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID paramete… Impresscms after 1.0.3 Fix from $1,6002009-01-23 HIGH 10.0 CVE-2008-3453 Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files." Impresscms No fix yet Fix from $1,9502008-08-04