CVE-2025-12920
- EPSS 0.06%
- Veröffentlicht 09.11.2025 23:15:46
- Zuletzt bearbeitet 26.11.2025 15:28:00
A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiat...
CVE-2025-10251
- EPSS 0.03%
- Veröffentlicht 11.09.2025 13:02:06
- Zuletzt bearbeitet 02.10.2025 19:38:41
A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the argument ids results in sql injection. It is possible to launch the attack remot...
CVE-2025-56630
- EPSS 0.03%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 08.09.2025 20:36:30
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.
CVE-2025-56435
- EPSS 0.1%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 15:59:26
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id.
CVE-2025-55422
- EPSS 0.07%
- Veröffentlicht 27.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 15:41:07
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
CVE-2025-55409
- EPSS 0.09%
- Veröffentlicht 25.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:12:28
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.
CVE-2025-55420
- EPSS 0.09%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:12:12
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code wh...
CVE-2025-50692
- EPSS 0.19%
- Veröffentlicht 07.08.2025 00:00:00
- Zuletzt bearbeitet 14.08.2025 19:48:25
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
CVE-2025-51650
- EPSS 0.12%
- Veröffentlicht 14.07.2025 00:00:00
- Zuletzt bearbeitet 15.07.2025 16:57:46
An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.
CVE-2025-6094
- EPSS 0.06%
- Veröffentlicht 15.06.2025 22:31:05
- Zuletzt bearbeitet 16.07.2025 17:00:11
A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Download.php. The manipulation of the argument ids leads to sql injection. The...