Tp5cms
by fmsdwifull
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19692 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type. | ||
| CVE-2018-15568 | Hig | 0.57 | 8.8 | 0.00 | Aug 20, 2018 | tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html. | ||
| CVE-2021-31280 | Med | 0.40 | 6.1 | 0.00 | Jun 14, 2023 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter. | ||
| CVE-2018-19693 | Med | 0.40 | 6.1 | 0.01 | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter. | ||
| CVE-2018-15566 | Med | 0.40 | 6.1 | 0.01 | Aug 20, 2018 | tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter. |
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
- risk 0.57cvss 8.8epss 0.00
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
- risk 0.40cvss 6.1epss 0.01
tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.