onefilecms CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

onefilecms vulnerability overview

Aggregates CVE and security vulnerability intelligence across all onefilecms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling; exposure may include vendor impact file overwrite in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-8408 OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice. [email protected] 4.9 0.19% 2019-02-17 2024-11-21
CVE-2018-13123 onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file. [email protected] 9.8 0.34% 2018-07-03 2024-11-21
CVE-2018-13122 onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI. [email protected] 6.5 0.05% 2018-07-03 2024-11-21
CVE-2018-12995 onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen. [email protected] 8.8 0.45% 2018-06-29 2024-11-21
CVE-2018-12994 onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen. [email protected] 8.8 0.45% 2018-06-29 2024-11-21
CVE-2018-12993 onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields. [email protected] 9.8 0.52% 2018-06-29 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence