Vulnerabilities (CVE)

Filtered by vendor Duxcms Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21881 1 Duxcms Project 1 Duxcms 2023-08-04 N/A 6.5 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.
CVE-2020-36763 1 Duxcms Project 1 Duxcms 2023-08-04 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom parameters when adding or editing a post.