greencms CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

greencms vulnerability overview

Aggregates CVE and security vulnerability intelligence across all greencms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk csrf, vendor risk path handling, and vendor risk input validation and related problems; some flaws may lead to vendor impact unexpected behavior and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2018-19376 An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI. [email protected] 6.5 0.06% 2018-11-20 2024-11-21
CVE-2018-19329 GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an m=admin&c=media&a=delfilehandle&id= call, related to the m=admin&c=media&a=restorefile delete button. [email protected] 4.9 0.51% 2018-11-17 2024-11-21
CVE-2018-12988 GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI. [email protected] 7.5 0.32% 2018-06-29 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence