CVE-2022-43118
- EPSS 0.31%
- Veröffentlicht 09.11.2022 16:15:18
- Zuletzt bearbeitet 01.05.2025 16:15:23
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
CVE-2021-41402
- EPSS 1.03%
- Veröffentlicht 16.06.2022 10:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:12
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
CVE-2021-41403
- EPSS 0.52%
- Veröffentlicht 15.06.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:26:12
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
CVE-2021-40902
- EPSS 0.19%
- Veröffentlicht 13.06.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:25:03
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
CVE-2021-42245
- EPSS 0.33%
- Veröffentlicht 06.06.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:27
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
CVE-2021-3745
- EPSS 0.38%
- Veröffentlicht 28.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:19
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
- EPSS 16.9%
- Veröffentlicht 23.08.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:47
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
CVE-2021-39609
- EPSS 0.57%
- Veröffentlicht 23.08.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:47
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
CVE-2017-1000428
- EPSS 0.33%
- Veröffentlicht 10.01.2018 02:29:31
- Zuletzt bearbeitet 21.11.2024 03:04:43
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
CVE-2017-8868
- EPSS 0.65%
- Veröffentlicht 10.05.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.