VYPR

puppyCMS

by PuppyCMS

CVEs (5)

  • CVE-2020-18890CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.

  • CVE-2020-18888HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.

  • CVE-2020-18889MedMay 6, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.

  • CVE-2018-15847MedAug 25, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.

  • CVE-2022-3464MedOct 12, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated…