Vulnerabilities (CVE)

Filtered by vendor Puppycms Subscribe
Filtered by product Puppycms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18888 1 Puppycms 1 Puppycms 2021-05-12 5.0 MEDIUM 7.5 HIGH
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
CVE-2020-18890 1 Puppycms 1 Puppycms 2021-05-12 7.5 HIGH 9.8 CRITICAL
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
CVE-2020-18889 1 Puppycms 1 Puppycms 2021-05-12 4.3 MEDIUM 6.5 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
CVE-2018-15847 1 Puppycms 1 Puppycms 2018-10-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.