VYPR

Taocms

by Taogo

CVEs (25)

  • CVE-2020-20725MedJun 20, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.

  • CVE-2021-44983MedFeb 4, 2022
    risk 0.32cvss 4.9epss 0.01

    In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

  • CVE-2022-23316MedFeb 4, 2022
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.

  • CVE-2021-44969MedFeb 10, 2022
    risk 0.31cvss 4.8epss 0.00

    Taocms v3.0.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Management Column component.

  • CVE-2021-25785MedDec 2, 2021
    risk 0.31cvss 4.8epss 0.01

    Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column.

Page 2 of 2