VYPR
Vendor

Nucleus

Products
3
CVEs
4
Across products
4
Status
Private

Products

3

Recent CVEs

4
  • CVE-2020-21474CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

  • CVE-2010-2314Jun 17, 2010
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details…

  • CVE-2007-5429Oct 12, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter.

  • CVE-2008-4446Oct 6, 2008
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.