Easycms
Products
1- 12 CVEs
Recent CVEs
12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23358 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement. | ||
| CVE-2020-24271 | Hig | 0.57 | 8.8 | 0.01 | Feb 1, 2021 | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***. | ||
| CVE-2019-6294 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2019 | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI. | ||
| CVE-2018-16345 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2018 | An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent. | ||
| CVE-2026-1105 | Hig | 0.47 | 7.3 | 0.00 | Jan 18, 2026 | A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be… | ||
| CVE-2018-12971 | Med | 0.42 | 6.5 | 0.00 | Jun 29, 2018 | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. | ||
| CVE-2026-3786 | Med | 0.41 | 6.3 | 0.00 | Mar 8, 2026 | A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order results in sql injection. The attack can be launched… | ||
| CVE-2026-3785 | Med | 0.41 | 6.3 | 0.00 | Mar 8, 2026 | A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order leads to sql injection. The attack can be initiated… | ||
| CVE-2018-17113 | Med | 0.40 | 6.1 | 0.01 | Sep 17, 2018 | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173. | ||
| CVE-2018-16759 | Med | 0.40 | 6.1 | 0.01 | Sep 9, 2018 | The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event. | ||
| CVE-2018-10374 | Med | 0.40 | 6.1 | 0.01 | Apr 25, 2018 | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request. | ||
| CVE-2018-16773 | Med | 0.31 | 4.8 | 0.01 | Sep 10, 2018 | EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field. |
- risk 0.64cvss 9.8epss 0.01
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be…
- risk 0.42cvss 6.5epss 0.00
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
- risk 0.41cvss 6.3epss 0.00
A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order results in sql injection. The attack can be launched…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order leads to sql injection. The attack can be initiated…
- risk 0.40cvss 6.1epss 0.01
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
- risk 0.40cvss 6.1epss 0.01
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
- risk 0.40cvss 6.1epss 0.01
EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.
- risk 0.31cvss 4.8epss 0.01
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.