Aggregates CVE and security vulnerability intelligence across all matteoiammarrone-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk sql injection, vendor risk cross-site scripting, and vendor risk path handling; exposure may include vendor impact data exposure in vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2010-4772 | Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php. | [email protected] | 4.3 | 0.14% | 2011-03-23 | 2026-04-29 |
| CVE-2010-4771 | SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.14% | 2011-03-23 | 2026-04-29 |
| CVE-2009-1502 | Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter. | [email protected] | 7.5 | 3.01% | 2009-05-01 | 2026-04-23 |
| CVE-2009-0864 | S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie. | [email protected] | 7.5 | 3.38% | 2009-03-10 | 2026-04-23 |
| CVE-2009-0863 | SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.60% | 2009-03-10 | 2026-04-23 |