VYPR

Aerocms

by Aerocms Project

CVEs (10)

  • CVE-2022-50895CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially…

  • CVE-2022-38305HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-46051HigDec 13, 2022
    risk 0.47cvss 7.2epss 0.01

    The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.

  • CVE-2022-46059MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-38812MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.02

    AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

  • CVE-2022-46061MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.00

    AeroCMS v0.0.1 is vulnerable to ClickJacking.

  • CVE-2022-27063MedApr 8, 2022
    risk 0.40cvss 6.1epss 0.01

    AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

  • CVE-2022-46047MedDec 13, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.

  • CVE-2022-45535MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.

  • CVE-2022-27062MedApr 8, 2022
    risk 0.31cvss 4.8epss 0.01

    AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.