Vulnerabilities (CVE)

Filtered by vendor Cuppacms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47990 1 Cuppacms 1 Cuppacms 2023-12-27 N/A 9.8 CRITICAL
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.
CVE-2022-25498 1 Cuppacms 1 Cuppacms 2023-08-08 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
CVE-2022-27985 1 Cuppacms 1 Cuppacms 2022-05-05 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CVE-2022-27984 1 Cuppacms 1 Cuppacms 2022-05-05 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CVE-2018-19559 1 Cuppacms 1 Cuppacms 2018-12-18 7.5 HIGH 9.8 CRITICAL
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.