iiSiLvEr/CVEs

iiSiLvEr/CVEs

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

5.4 MEDIUM3.5 LOW

CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

8.8 HIGH6.5 MEDIUM

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.