Aggregates CVE and security vulnerability intelligence across all dilicms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2019-8440 | An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_logo. | [email protected] | 4.8 | 0.24% | 2019-03-07 | 2024-11-21 |
| CVE-2019-8439 | An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain. | [email protected] | 5.4 | 0.21% | 2019-03-07 | 2024-11-21 |
| CVE-2019-8438 | An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name. | [email protected] | 4.8 | 0.24% | 2019-03-07 | 2024-11-21 |
| CVE-2018-19291 | An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI. | [email protected] | 6.5 | 0.08% | 2018-11-15 | 2024-11-21 |
| CVE-2018-18210 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. | [email protected] | 6.1 | 0.24% | 2018-10-10 | 2024-11-21 |
| CVE-2018-18209 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter. | [email protected] | 6.1 | 0.24% | 2018-10-10 | 2024-11-21 |
| CVE-2018-10430 | An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php. | [email protected] | 4.8 | 0.24% | 2018-04-26 | 2024-11-21 |