Vulnerabilities (CVE)

Filtered by vendor Flycms Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52074 1 Flycms Project 1 Flycms 2024-01-11 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.
CVE-2023-52073 1 Flycms Project 1 Flycms 2024-01-11 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.
CVE-2023-52072 1 Flycms Project 1 Flycms 2024-01-11 N/A 8.8 HIGH
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.
CVE-2024-21732 1 Flycms Project 1 Flycms 2024-01-08 N/A 6.1 MEDIUM
FlyCms through abbaa5a allows XSS via the permission management feature.
CVE-2020-19613 1 Flycms Project 1 Flycms 2021-04-06 5.0 MEDIUM 7.5 HIGH
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.