ESPCMS
by ESPCMS
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44088 | Cri | 0.65 | 9.8 | 0.20 | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | ||
| CVE-2022-44089 | Cri | 0.64 | 9.8 | 0.01 | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. | ||
| CVE-2022-44087 | Cri | 0.64 | 9.8 | 0.01 | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. | ||
| CVE-2023-23007 | Hig | 0.47 | 7.2 | 0.01 | Feb 17, 2023 | An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added. | ||
| CVE-2022-33085 | Hig | 0.47 | 7.2 | 0.02 | Jun 30, 2022 | ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates. | ||
| CVE-2020-18404 | Med | 0.31 | 4.8 | 0.00 | Jun 27, 2023 | An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter. |
- risk 0.65cvss 9.8epss 0.20
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
- risk 0.64cvss 9.8epss 0.01
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
- risk 0.64cvss 9.8epss 0.01
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
- risk 0.47cvss 7.2epss 0.02
ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.