VYPR

299Ko CMS

by 299Ko CMS

CVEs (3)

  • CVE-2026-71249MedAug 5, 2026
    risk 0.40cvss 6.1epss 0.00

    299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var) echoes…

  • CVE-2025-10232MedSep 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controllers/FileManagerAPIController.php. Executing manipulation can lead to path traversal. It is possible to launch the attack remotely.…

  • CVE-2025-8265MedJul 28, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File Management. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit…