Nukeviet

Nukeviet

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 22.05.2026 21:45:21
  • Zuletzt bearbeitet 26.05.2026 19:37:00

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on cli...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 09.08.2025 19:32:06
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation lea...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 10.06.2024 15:15:52
  • Zuletzt bearbeitet 15.09.2025 14:12:24

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 10.06.2024 15:15:52
  • Zuletzt bearbeitet 15.09.2025 14:12:50

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

  • EPSS 0.5%
  • Veröffentlicht 13.11.2022 10:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:39

A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the function filterAttr of the file vendor/vinades/nukeviet/Core/Request.php of the component Data URL Handler. The manipulation of the ar...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 21.06.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:30

There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.

Exploit
  • EPSS 1.58%
  • Veröffentlicht 30.07.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:12:51

SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

Exploit
  • EPSS 1.58%
  • Veröffentlicht 30.07.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:12:51

SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.

  • EPSS 0.62%
  • Veröffentlicht 30.07.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:13:24

Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.

  • EPSS 2.54%
  • Veröffentlicht 31.12.2020 05:15:10
  • Zuletzt bearbeitet 21.11.2024 04:48:35

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).