VYPR

CXUUCMS V3

by CXUUCMS

CVEs (3)

  • CVE-2020-28091Nov 18, 2020
    risk 0.04cvss epss 0.07

    cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.

  • CVE-2020-29250Dec 27, 2020
    risk 0.00cvss epss 0.00

    CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.

  • CVE-2020-35346Dec 26, 2020
    risk 0.00cvss epss 0.00

    CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add.