• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-19907
2018-12-26
N/A
8.8 HIGH
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
CVE-2018-19906
2019-02-25
N/A
5.4 MEDIUM
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
CVE-2018-19905
2019-02-26
N/A
5.4 MEDIUM
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
CVE-2018-19904
2019-02-26
N/A
6.1 MEDIUM
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
CVE-2018-19903
2019-02-25
N/A
6.1 MEDIUM
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field.
CVE-2018-19902
2019-02-25
N/A
4.8 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter.
CVE-2018-19901
2019-02-25
N/A
4.8 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.
CVE-2018-1990
2019-05-15
N/A
5.3 MEDIUM
IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially crafted HTTP request. IBM X-Force ID: 154283.
CVE-2018-19898
2018-12-26
N/A
8.8 HIGH
ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action.
CVE-2018-19897
2018-12-26
N/A
7.2 HIGH
ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.
« Previous 1 … 2,080 2,081 2,082 2,083 2,084 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE