CVE-2026-30661
- EPSS 0.04%
- Veröffentlicht 24.03.2026 00:00:00
- Zuletzt bearbeitet 25.03.2026 20:53:28
iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
CVE-2025-15394
- EPSS 0.06%
- Veröffentlicht 31.12.2025 19:15:43
- Zuletzt bearbeitet 13.01.2026 20:38:18
A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be lau...
CVE-2023-40953
- EPSS 0.07%
- Veröffentlicht 08.09.2023 03:15:08
- Zuletzt bearbeitet 21.11.2024 08:20:20
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-39806
- EPSS 0.07%
- Veröffentlicht 10.08.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:57
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
CVE-2023-39805
- EPSS 0.07%
- Veröffentlicht 10.08.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:57
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
CVE-2022-41496
- EPSS 0.38%
- Veröffentlicht 13.10.2022 21:15:10
- Zuletzt bearbeitet 15.05.2025 16:15:28
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
CVE-2021-44978
- EPSS 2.67%
- Veröffentlicht 04.02.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:46
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
CVE-2021-44977
- EPSS 0.43%
- Veröffentlicht 04.02.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:31:46
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
CVE-2020-21141
- EPSS 0.14%
- Veröffentlicht 12.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:27
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
CVE-2020-26641
- EPSS 0.15%
- Veröffentlicht 28.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:20:10
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.