Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ofcms MEDIUM 6.5
CVE-2024-48235

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

No fix yet
Fix from $1,600 2024-10-25
Ofcms MEDIUM 6.5
CVE-2024-48236

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-…

No fix yet
Fix from $1,600 2024-10-25
Ofcms CRITICAL 9.8
CVE-2024-34256

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

No fix yet
Fix from $2,300 2024-05-14
Ofcms MEDIUM 5.4
CVE-2023-51807

Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title additi…

No fix yet
Fix from $1,600 2024-01-16
Ofcms HIGH 8.8
CVE-2023-24760

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.

No fix yet
Fix from $1,950 2023-03-16
Ofcms MEDIUM 6.1
CVE-2022-29653

OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.

Mitigation only
Fix from $1,600 2022-06-02
Ofcms MEDIUM 5.4
CVE-2022-27960

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify …

No fix yet
Fix from $1,600 2022-04-10
Ofcms MEDIUM 5.4
CVE-2022-27961

A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a cra…

No fix yet
Fix from $1,600 2022-04-10