VYPR
Vendor

TE Informatics

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2018-25431HigJun 1, 2026
    risk 0.46cvss 7.1epss 0.00

    No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious…

  • CVE-2024-4658MedOct 10, 2024
    risk 0.45cvss epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS allows SQL Injection. This issue affects Nova CMS: before 5.0.

  • CVE-2024-2010MedSep 12, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS. This issue affects V5: before 6.2.

  • CVE-2012-1200Feb 18, 2012
    risk 0.03cvss epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to…

  • CVE-2018-19902Dec 31, 2018
    risk 0.00cvss epss 0.01

    No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter.

  • CVE-2018-19901Dec 31, 2018
    risk 0.00cvss epss 0.01

    No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.

  • CVE-2018-18868Oct 31, 2018
    risk 0.00cvss epss 0.01

    No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.