genixcms 漏洞與 CVE 列表(18)

產品(CPE): — CVE 數: 18

genixcms 漏洞概覽

彙總 genixcms 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。

常見弱點模式包括 跨站腳本、SQL 注入與輸入驗證問題,在 生產負載與軟體部署 使用場景中可能帶來 工作階段劫持、資料外洩與異常行為 等風險。

相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。

漏洞分布趨勢(近 24 個月)

顯示 11818 CVE 數
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2017-14740 Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu. [email protected] 4.8 0.17% 2018-04-26 2024-11-21
CVE-2017-17431 GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765. [email protected] 6.1 0.24% 2017-12-05 2026-05-13
CVE-2017-14765 In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request. [email protected] 6.1 0.24% 2017-09-27 2026-05-13
CVE-2017-14764 In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module. [email protected] 8.8 0.83% 2017-09-27 2026-05-13
CVE-2017-14763 In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme. [email protected] 8.8 0.74% 2017-09-27 2026-05-13
CVE-2017-14762 In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter. [email protected] 6.1 0.24% 2017-09-27 2026-05-13
CVE-2017-14761 In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter. [email protected] 6.1 0.24% 2017-09-27 2026-05-13
CVE-2017-14231 GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php. [email protected] 5.3 0.61% 2017-09-10 2026-05-13
CVE-2017-8827 forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests. [email protected] 9.1 0.46% 2017-05-08 2026-05-13
CVE-2017-8780 GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element. [email protected] 4.8 0.22% 2017-05-04 2026-05-13
CVE-2017-8762 GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element. [email protected] 5.4 0.32% 2017-05-03 2026-05-13
CVE-2017-8388 GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request. [email protected] 5.3 0.43% 2017-05-01 2026-05-13
CVE-2017-8377 GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter. [email protected] 8.8 0.45% 2017-05-01 2026-05-13
CVE-2017-8376 GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator. [email protected] 5.4 0.32% 2017-05-01 2026-05-13
CVE-2017-5346 SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php. [email protected] 7.2 1.08% 2017-01-12 2026-05-06
CVE-2016-10096 SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter. [email protected] 7.3 0.50% 2017-01-01 2026-05-06
CVE-2015-2679 Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php. [email protected] 7.5 8.34% 2015-03-23 2026-05-06
CVE-2015-2678 Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php. [email protected] 4.3 14.56% 2015-03-23 2026-05-06
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
cvelogic Threat Intelligence