Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cuppacms CRITICAL 9.8
CVE-2023-47990

SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via…

No fix yet
Fix from $2,300 2023-12-20
Cuppacms CRITICAL 9.8
CVE-2023-39681

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul…

No fix yet
Fix from $2,300 2023-09-05
Cuppacms HIGH 8.8
CVE-2021-29368

Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access …

Fix: after 2019-11-12
Fix from $1,950 2023-01-20
Cuppacms HIGH 8.8
CVE-2022-37190EPSS 46%

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.p…

No fix yet
Fix from $1,950 2022-09-13
Cuppacms MEDIUM 6.5
CVE-2022-37191

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using…

No fix yet
Fix from $1,600 2022-09-13
Cuppacms CRITICAL 9.8
CVE-2022-38296

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

No fix yet
Fix from $2,300 2022-09-12
Cuppacms MEDIUM 6.1
CVE-2022-38295

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attack…

No fix yet
Fix from $1,600 2022-09-12
Cuppacms HIGH 7.5
CVE-2022-34121

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

No fix yet
Fix from $1,950 2022-07-27
Cuppacms CRITICAL 9.8
CVE-2022-27984EPSS 7%

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/…

Mitigation only
Fix from $2,300 2022-04-26
Cuppacms CRITICAL 9.8
CVE-2022-27985EPSS 7%

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

Mitigation only
Fix from $2,300 2022-04-26
Cuppacms CRITICAL 9.8
CVE-2022-25495

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c…

No fix yet
Fix from $2,300 2022-03-15
Cuppacms CRITICAL 9.8
CVE-2022-25498

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

No fix yet
Fix from $2,300 2022-03-15
Cuppacms HIGH 7.8
CVE-2022-25485EPSS 8%

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

No fix yet
Fix from $1,950 2022-03-15
Cuppacms HIGH 7.8
CVE-2022-25486EPSS 10%

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

No fix yet
Fix from $1,950 2022-03-15
Cuppacms MEDIUM 5.3
CVE-2022-25497

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

No fix yet
Fix from $1,600 2022-03-15
Cuppacms HIGH 7.5
CVE-2022-25401

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbi…

No fix yet
Fix from $1,950 2022-02-24
Cuppacms HIGH 8.1
CVE-2022-24647

Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

No fix yet
Fix from $1,950 2022-02-10
Cuppacms HIGH 7.5
CVE-2022-24264EPSS 7%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

No fix yet
Fix from $1,950 2022-01-31
Cuppacms HIGH 7.5
CVE-2022-24265EPSS 7%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 …

No fix yet
Fix from $1,950 2022-01-31
Cuppacms HIGH 7.5
CVE-2022-24266EPSS 6%

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

Mitigation only
Fix from $1,950 2022-01-31
Cuppacms HIGH 8.8
CVE-2021-3376

An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST reque…

Fix: 31+
Fix from $1,950 2021-12-14
Cuppacms HIGH 8.8
CVE-2020-26048

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and throu…

Fix: 2019-11-12+
Fix from $1,950 2020-10-05
Cuppacms MEDIUM 5.4
CVE-2018-19918

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

No fix yet
Fix from $1,600 2018-12-31
Cuppacms CRITICAL 9.8
CVE-2018-19559

CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

Fix: 2018-11-12+
Fix from $2,300 2018-11-26