Vulnerabilities (CVE)

Filtered by vendor Cmseasy Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42643 1 Cmseasy 1 Cmseasy 2022-05-26 6.5 MEDIUM 8.8 HIGH
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.
CVE-2018-11679 1 Cmseasy 1 Cmseasy 2018-07-09 6.8 MEDIUM 8.8 HIGH
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.