VYPR

Icms

by Idreamsoft

Source repositories

CVEs (49)

  • CVE-2018-13865MedJul 10, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.

  • CVE-2019-8902MedFeb 18, 2019
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.

  • CVE-2018-10250MedApr 20, 2018
    risk 0.35cvss 5.4epss 0.01

    iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.

  • CVE-2018-9925MedApr 10, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.

  • CVE-2018-9922MedApr 10, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.

  • CVE-2025-15394MedDec 31, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be launched remotely. The exploit…

  • CVE-2005-4397Dec 20, 2005
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter.

  • CVE-2005-4396Dec 20, 2005
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.

  • CVE-2005-3574Nov 16, 2005
    risk 0.00cvss —epss 0.01

    PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.

Page 3 of 3