Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2020-20067: Bug: file upload vulnerability · Issue #1 · a932278490/ebcms

File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.

CVE
#vulnerability#git
CVE-2020-20413: WUZHICMS-SQL-Injection/README.md at master · SuperSalsa20/WUZHICMS-SQL-Injection

SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

CVE-2020-20918: Pluck-4.7.10-dev2 admin background exists a remote command execution vulnerability when creating a new web page · Issue #80 · pluck-cms/pluck

An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

CVE-2020-20725: Cross Site Scripting · Issue #2 · taogogo/taocms

Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.

CVE-2020-20735

File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

CVE-2020-20726: There is a CSRF vulnerability that can add an administrator account · Issue #51 · GilaCMS/gila

Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.

CVE-2020-20697: There is a critical vulnerability in NodCMS · Issue #41 · khodakhah/nodcms

Cross Site Scripting vulnerability in khodakhah NodCMS v.3.0 allows a remote attacker to execute arbitrary code and gain access to senstivie information via a crafted script to the address parameter.

CVE-2020-21485: Alluxio v1.8.1 reflected xss vulnerability · Issue #10552 · Alluxio/alluxio

Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.

CVE-2023-34541: Arbitrary code execution in load_prompt · Issue #4849 · hwchase17/langchain

Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.

CVE-2020-21246: Cross-Site Scripting (XSS) · Issue #6 · yongshengli/yiicms

Cross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function.