Cmseasy
Products
1- 23 CVEs
Recent CVEs
23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34880 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion. | ||
| CVE-2021-42643 | Hig | 0.57 | 8.8 | 0.02 | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability. | ||
| CVE-2018-11679 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin. | ||
| CVE-2024-34315 | Hig | 0.49 | 7.5 | 0.01 | May 7, 2024 | CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files. | ||
| CVE-2024-31551 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2024 | Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request. | ||
| CVE-2020-18406 | Hig | 0.49 | 7.5 | 0.00 | Jun 27, 2023 | An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data. | ||
| CVE-2024-32163 | Med | 0.42 | 6.4 | 0.00 | Apr 17, 2024 | CMSeasy 7.7.7.9 is vulnerable to code execution. | ||
| CVE-2021-42644 | Med | 0.42 | 6.5 | 0.01 | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability. | ||
| CVE-2018-11680 | Med | 0.42 | 6.5 | 0.00 | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate. | ||
| CVE-2025-55910 | Med | 0.41 | 6.3 | 0.00 | Sep 19, 2025 | CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php. | ||
| CVE-2024-0523 | Med | 0.41 | 6.3 | 0.01 | Jan 14, 2024 | A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql injection. The attack can be… | ||
| CVE-2019-8434 | Med | 0.40 | 6.1 | 0.01 | Feb 18, 2019 | In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter. | ||
| CVE-2019-8432 | Med | 0.40 | 6.1 | 0.01 | Feb 18, 2019 | In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter. | ||
| CVE-2025-1106 | Med | 0.35 | 5.4 | 0.01 | Feb 7, 2025 | A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit… | ||
| CVE-2025-0973 | Med | 0.35 | 5.4 | 0.01 | Feb 3, 2025 | A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument… | ||
| CVE-2024-34314 | Med | 0.32 | 4.9 | 0.00 | May 7, 2024 | CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files. | ||
| CVE-2024-25828 | Med | 0.32 | 4.9 | 0.01 | Feb 22, 2024 | cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php. | ||
| CVE-2025-15148 | Med | 0.31 | 4.7 | 0.00 | Dec 28, 2025 | A flaw has been found in CmsEasy up to 7.7.7. Affected is the function savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Page. Executing a manipulation of the argument content/tempdata can lead to code injection. The attack… | ||
| CVE-2025-1336 | Med | 0.28 | 4.3 | 0.01 | Feb 16, 2025 | A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admin.php. The manipulation of the argument imgname leads to path traversal. The attack can be launched… | ||
| CVE-2025-1335 | Med | 0.28 | 4.3 | 0.01 | Feb 16, 2025 | A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admin/file_admin.php. The manipulation of the argument imgname leads to path traversal. It is possible to launch the attack remotely.… |
- risk 0.64cvss 9.8epss 0.01
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
- risk 0.57cvss 8.8epss 0.02
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.
- risk 0.49cvss 7.5epss 0.01
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.
- risk 0.49cvss 7.5epss 0.01
Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
- risk 0.42cvss 6.4epss 0.00
CMSeasy 7.7.7.9 is vulnerable to code execution.
- risk 0.42cvss 6.5epss 0.01
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.
- risk 0.41cvss 6.3epss 0.00
CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql injection. The attack can be…
- risk 0.40cvss 6.1epss 0.01
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
- risk 0.40cvss 6.1epss 0.01
In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.
- risk 0.35cvss 5.4epss 0.01
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit…
- risk 0.35cvss 5.4epss 0.01
A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument…
- risk 0.32cvss 4.9epss 0.00
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.
- risk 0.32cvss 4.9epss 0.01
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
- risk 0.31cvss 4.7epss 0.00
A flaw has been found in CmsEasy up to 7.7.7. Affected is the function savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Page. Executing a manipulation of the argument content/tempdata can lead to code injection. The attack…
- risk 0.28cvss 4.3epss 0.01
A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admin.php. The manipulation of the argument imgname leads to path traversal. The attack can be launched…
- risk 0.28cvss 4.3epss 0.01
A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admin/file_admin.php. The manipulation of the argument imgname leads to path traversal. It is possible to launch the attack remotely.…