VYPR
Vendor

ESPCMS

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2022-44088CriNov 10, 2022
    risk 0.65cvss 9.8epss 0.20

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.

  • CVE-2022-44089CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.02

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.

  • CVE-2022-44087CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.02

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.

  • CVE-2023-23007HigFeb 17, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.

  • CVE-2022-33085HigJun 30, 2022
    risk 0.47cvss 7.2epss 0.02

    ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.

  • CVE-2020-18404MedJun 27, 2023
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.

  • CVE-2023-0246LowJan 12, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown function of the component Content Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been…