Vendor
Gofrendiasgard
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25431 | Hig | 0.46 | 7.1 | 0.00 | Jun 1, 2026 | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious… | ||
| CVE-2018-18868 | Med | 0.40 | 6.1 | 0.01 | Oct 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter. | ||
| CVE-2018-19902 | Med | 0.31 | 4.8 | 0.01 | Dec 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter. | ||
| CVE-2018-19901 | Med | 0.31 | 4.8 | 0.01 | Dec 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter. |
- risk 0.46cvss 7.1epss 0.00
No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious…
- risk 0.40cvss 6.1epss 0.01
No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.
- risk 0.31cvss 4.8epss 0.01
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter.
- risk 0.31cvss 4.8epss 0.01
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.