Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Greencms HIGH 8.8
CVE-2019-25573

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious cod…

Fix: after 2.3.0603
Fix from $1,950 2026-03-21
Greencms MEDIUM 6.5
CVE-2019-25574

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting di…

Fix: after 2.3.0603
Fix from $1,600 2026-03-21
Greencms MEDIUM 6.5
CVE-2025-15187

A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Pe…

Fix: after 2.3
Fix from $1,600 2025-12-29
Greencms CRITICAL 9.8
CVE-2025-9415

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The man…

Fix: after 2.3.0603
Fix from $2,300 2025-08-25
Greencms MEDIUM 5.4
CVE-2024-22570

A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary we…

Mitigation only
Fix from $1,600 2024-01-29
Greencms HIGH 8.0
CVE-2020-21366

Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.

No fix yet
Fix from $1,950 2023-06-20
Greencms HIGH 8.1
CVE-2022-28918

GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.

No fix yet
Fix from $1,950 2022-04-26
Greencms HIGH 7.5
CVE-2018-12604EPSS 13%

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

No fix yet
Fix from $1,950 2018-06-20
Greencms HIGH 8.8
CVE-2018-11670

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content para…

No fix yet
Fix from $1,950 2018-06-01
Greencms HIGH 8.8
CVE-2018-11671

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserha…

No fix yet
Fix from $1,950 2018-06-01