Snewscms
Products
2- 8 CVEs
- 2 CVEs
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-20052 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2026 | Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and… | ||
| CVE-2016-20051 | Med | 0.34 | 5.3 | 0.00 | Apr 4, 2026 | Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form… | ||
| CVE-2010-2926 | 0.03 | — | 0.01 | Jul 30, 2010 | SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||
| CVE-2008-1413 | 0.03 | — | 0.01 | Mar 20, 2008 | Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |||
| CVE-2007-0261 | 0.03 | — | 0.05 | Jan 16, 2007 | snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the… | |||
| CVE-2006-0715 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |||
| CVE-2005-3853 | 0.03 | — | 0.01 | Nov 27, 2005 | SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php. | |||
| CVE-2011-2706 | 0.00 | — | 0.01 | Jan 14, 2020 | A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71. | |||
| CVE-2007-5303 | 0.00 | — | 0.01 | Oct 9, 2007 | Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter. | |||
| CVE-2006-0716 | 0.00 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. |
- risk 0.64cvss 9.8epss 0.01
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and…
- risk 0.34cvss 5.3epss 0.00
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form…
- CVE-2010-2926Jul 30, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
- CVE-2008-1413Mar 20, 2008risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
- CVE-2007-0261Jan 16, 2007risk 0.03cvss —epss 0.05
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the…
- CVE-2006-0715Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
- CVE-2005-3853Nov 27, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
- CVE-2011-2706Jan 14, 2020risk 0.00cvss —epss 0.01
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
- CVE-2007-5303Oct 9, 2007risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.
- CVE-2006-0716Feb 15, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.