VYPR

NukeViet CMS

by Vinades

CVEs (4)

  • CVE-2020-21808CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

  • CVE-2020-21809CriJul 30, 2021
    risk 0.57cvss 9.8epss 0.02

    SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.

  • CVE-2026-49259higJul 13, 2026
    risk 0.45cvss epss

    ## Summary A stored cross-site scripting (XSS) vulnerability exists in NukeViet CMS versions 4.x through 4.5.08. A low-privileged authenticated user can store a JavaScript payload in their profile's display name fields. The payload executes in the browser of any visitor —…

  • CVE-2020-22765MedJul 30, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.