VYPR

by Anchorcms

Source repositories

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-5060Med0.406.10.00Sep 7, 2017Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
CVE-2015-56870.000.01Oct 5, 2015system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
CVE-2014-91820.000.00Dec 2, 2014models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.