CVE-2024-57099
- EPSS 1.46%
- Veröffentlicht 03.02.2025 20:15:34
- Zuletzt bearbeitet 13.05.2025 19:57:33
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of t...
CVE-2024-57097
- EPSS 0.2%
- Veröffentlicht 03.02.2025 20:15:33
- Zuletzt bearbeitet 13.05.2025 19:15:59
ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-12666
- EPSS 0.1%
- Veröffentlicht 16.12.2024 20:15:09
- Zuletzt bearbeitet 19.12.2024 15:01:00
A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to imp...
CVE-2024-12503
- EPSS 0.32%
- Veröffentlicht 12.12.2024 02:15:22
- Zuletzt bearbeitet 13.12.2024 17:13:37
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross s...
CVE-2024-48180
- EPSS 0.36%
- Veröffentlicht 16.10.2024 21:15:13
- Zuletzt bearbeitet 28.04.2025 17:34:22
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
CVE-2024-8145
- EPSS 0.1%
- Veröffentlicht 25.08.2024 06:15:03
- Zuletzt bearbeitet 18.09.2024 15:34:47
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to ...
CVE-2024-8144
- EPSS 0.13%
- Veröffentlicht 25.08.2024 04:15:03
- Zuletzt bearbeitet 18.09.2024 18:24:46
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can...
CVE-2022-25581
- EPSS 0.49%
- Veröffentlicht 18.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:52:23
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.