CVE-2022-50912
- EPSS 0.19%
- Veröffentlicht 13.01.2026 22:51:51
- Zuletzt bearbeitet 03.02.2026 19:26:43
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.php...
CVE-2023-37785
- EPSS 0.08%
- Veröffentlicht 13.07.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:12:15
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.
CVE-2022-26986
- EPSS 1.42%
- Veröffentlicht 05.04.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:54:54
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an atta...
CVE-2021-26601
- EPSS 11.92%
- Veröffentlicht 28.03.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 05:56:33
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
CVE-2021-26600
- EPSS 1.21%
- Veröffentlicht 28.03.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 05:56:33
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
CVE-2021-26599
- EPSS 4.64%
- Veröffentlicht 28.03.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 05:56:33
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
CVE-2021-26598
- EPSS 76.07%
- Veröffentlicht 28.03.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 05:56:33
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
CVE-2022-24977
- EPSS 28.07%
- Veröffentlicht 14.02.2022 12:15:27
- Zuletzt bearbeitet 21.11.2024 06:51:29
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_P...
CVE-2021-28088
- EPSS 0.16%
- Veröffentlicht 11.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:03
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.
CVE-2020-17551
- EPSS 0.33%
- Veröffentlicht 07.10.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:19
ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.