Siberiancms
Products
1- 7 CVEs
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-41702 | Cri | 0.64 | 9.8 | 0.00 | Jul 30, 2024 | SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ||
| CVE-2023-39378 | Hig | 0.57 | 8.8 | 0.01 | Sep 27, 2023 | SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user | ||
| CVE-2023-39375 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges | ||
| CVE-2023-39377 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2023 | SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method | ||
| CVE-2023-39376 | Med | 0.42 | 6.5 | 0.00 | Sep 27, 2023 | SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network | ||
| CVE-2017-6906 | Med | 0.40 | 6.1 | 0.01 | Mar 15, 2017 | An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context… | ||
| CVE-2025-1105 | Med | 0.28 | 4.3 | 0.00 | Feb 7, 2025 | A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. The attack… |
- risk 0.64cvss 9.8epss 0.00
SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- risk 0.57cvss 8.8epss 0.01
SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user
- risk 0.49cvss 7.5epss 0.01
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
- risk 0.47cvss 7.2epss 0.01
SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method
- risk 0.42cvss 6.5epss 0.00
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. The attack…