This page aggregates publicly disclosed CVE and security risk information related to eleanor-cms, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2018-18717 | An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI. | [email protected] | 4.8 | 0.24% | 2018-10-29 | 2024-11-21 |
| CVE-2014-9180 | Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING. | [email protected] | 5.0 | 8.44% | 2014-12-02 | 2026-05-06 |