Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pad Cms HIGH 8.8
CVE-2025-8122

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…

Fix: after 1.2.1
Fix from $1,950 2025-09-30
Pad Cms CRITICAL 9.8
CVE-2025-8120

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files o…

Fix: after 1.2.1
Fix from $2,300 2025-09-30
Pad Cms HIGH 8.8
CVE-2025-8121

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…

Fix: after 1.2.1
Fix from $1,950 2025-09-30
Pad Cms MEDIUM 6.5
CVE-2025-8118

PAD CMS implements weak client-side brute-force protection by utilizing two cookies:  login_count and login_timeout. Information about attempt count …

Fix: after 1.2.1
Fix from $1,600 2025-09-30
Pad Cms CRITICAL 9.8
CVE-2025-7063

Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of…

Fix: after 1.2.1
Fix from $2,300 2025-09-30
Pad Cms CRITICAL 9.8
CVE-2025-7065

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files o…

Fix: after 1.2.1
Fix from $2,300 2025-09-30
Pad Cms HIGH 7.5
CVE-2025-8117

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password fun…

Fix: after 1.2.1
Fix from $1,950 2025-09-30
Pad Cms MEDIUM 6.1
CVE-2025-8116

PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbi…

Fix: after 1.2.1
Fix from $1,600 2025-09-30