chshcms cscms CVE Vulnerabilities (21)

CVEs: 21 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting chshcms cscms (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 21 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-30898 A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. [email protected] 6.5 0.54% 2022-06-09 2024-11-21
CVE-2022-28552 Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin. [email protected] 8.8 0.80% 2022-05-04 2024-11-21
CVE-2022-27369 Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy. [email protected] 7.2 0.81% 2022-04-15 2024-11-21
CVE-2022-27368 Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan. [email protected] 7.2 0.81% 2022-04-15 2024-11-21
CVE-2022-27367 Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del. [email protected] 7.2 0.81% 2022-04-15 2024-11-21
CVE-2022-27366 Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy. [email protected] 7.2 0.81% 2022-04-15 2024-11-21
CVE-2022-27365 Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del. [email protected] 7.2 0.92% 2022-04-15 2024-11-21
CVE-2022-27090 Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter. [email protected] 5.4 0.41% 2022-03-21 2024-11-21
CVE-2020-28103 cscms v4.1 allows for SQL injection via the "page_del" function. [email protected] 9.8 1.10% 2022-01-11 2024-11-21
CVE-2020-28102 cscms v4.1 allows for SQL injection via the "js_del" function. [email protected] 9.8 1.21% 2022-01-11 2024-11-21
CVE-2020-21238 An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks. [email protected] 9.8 0.94% 2021-12-27 2024-11-21
CVE-2020-22848 A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands. [email protected] 9.8 2.78% 2021-08-30 2024-11-21
CVE-2019-9598 An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds. [email protected] 6.5 0.51% 2019-03-07 2024-11-21
CVE-2019-6779 Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links. [email protected] 8.1 0.45% 2019-01-24 2024-11-21
CVE-2018-17126 CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. [email protected] 9.8 3.23% 2018-09-17 2024-11-21
CVE-2018-17125 CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. [email protected] 7.5 1.41% 2018-09-17 2024-11-21
CVE-2018-16732 \upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save. [email protected] 8.8 0.52% 2018-09-08 2024-11-21
CVE-2018-16731 CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data. [email protected] 9.8 1.49% 2018-09-08 2024-11-21
CVE-2018-16730 \upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name. [email protected] 6.1 0.70% 2018-09-08 2024-11-21
CVE-2018-16448 Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save. [email protected] 8.8 0.49% 2018-09-04 2024-11-21
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence