Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Otcms HIGH 7.5
CVE-2026-30637

Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allo…

Fix: after 7.66
Fix from $1,950 2026-03-27
Otcms HIGH 7.2
CVE-2023-6772

A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The…

No fix yet
Fix from $1,950 2023-12-13
Otcms HIGH 7.5
CVE-2023-3239

A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the file admin/readDeal.php?m…

Fix: after 6.62
Fix from $1,950 2023-06-14
Otcms HIGH 7.5
CVE-2023-3241

A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/…

Fix: after 6.62
Fix from $1,950 2023-06-14
Otcms MEDIUM 6.5
CVE-2023-3240

A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an unknown functionality of the f…

Fix: after 6.62
Fix from $1,600 2023-06-14
Otcms CRITICAL 9.8
CVE-2023-3237

A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument usern…

Fix: after 6.62
Fix from $2,300 2023-06-14
Otcms CRITICAL 9.8
CVE-2023-3238

A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/…

Fix: after 6.62
Fix from $2,300 2023-06-14
Otcms CRITICAL 9.8
CVE-2023-1797

A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.…

No fix yet
Fix from $2,300 2023-04-02
Otcms CRITICAL 9.8
CVE-2023-1634

A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the…

No fix yet
Fix from $2,300 2023-03-25
Otcms MEDIUM 6.1
CVE-2023-1635

A vulnerability was found in OTCMS 6.72. It has been declared as problematic. Affected by this vulnerability is the function AutoRun of the file apiR…

No fix yet
Fix from $1,600 2023-03-25
Otcms HIGH 7.2
CVE-2019-17370

OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block t…

No fix yet
Fix from $1,950 2019-10-09
Otcms MEDIUM 6.5
CVE-2019-17369

OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superad…

No fix yet
Fix from $1,600 2019-10-09
Otcms MEDIUM 6.1
CVE-2019-13971

OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.

No fix yet
Fix from $1,600 2019-07-19
Otcms HIGH 8.1
CVE-2018-17364

OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

No fix yet
Fix from $1,950 2018-09-23
Otcms MEDIUM 6.1
CVE-2018-17085

An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

No fix yet
Fix from $1,600 2018-09-16
Otcms MEDIUM 6.1
CVE-2018-17086

An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.

No fix yet
Fix from $1,600 2018-09-16
Otcms MEDIUM 6.1
CVE-2018-8973

OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.

No fix yet
Fix from $1,600 2018-03-24