CVE-2025-25988
- EPSS 0.07%
- Veröffentlicht 14.02.2025 17:15:21
- Zuletzt bearbeitet 18.04.2025 01:53:55
Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.
CVE-2025-25990
- EPSS 0.07%
- Veröffentlicht 14.02.2025 17:15:21
- Zuletzt bearbeitet 18.04.2025 01:50:40
Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVE-2025-25991
- EPSS 0.05%
- Veröffentlicht 14.02.2025 17:15:21
- Zuletzt bearbeitet 18.04.2025 01:48:51
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVE-2024-51055
- EPSS 1%
- Veröffentlicht 08.11.2024 19:15:06
- Zuletzt bearbeitet 18.04.2025 14:38:02
An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.
CVE-2022-43234
- EPSS 0.76%
- Veröffentlicht 16.11.2022 15:15:15
- Zuletzt bearbeitet 30.04.2025 16:15:26
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-28586
- EPSS 0.22%
- Veröffentlicht 25.04.2022 13:15:49
- Zuletzt bearbeitet 21.11.2024 06:57:33
XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars.
CVE-2021-43478
- EPSS 0.27%
- Veröffentlicht 31.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:17
A vulnerability exists in Hoosk 1.8.0 in /install/index.php, due to a failure to check if config.php already exists in the root directory, which could let a malicious user reinstall the website.
CVE-2020-26041
- EPSS 2.65%
- Veröffentlicht 30.09.2020 18:15:26
- Zuletzt bearbeitet 21.11.2024 05:19:05
An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
CVE-2020-26042
- EPSS 0.26%
- Veröffentlicht 30.09.2020 18:15:26
- Zuletzt bearbeitet 21.11.2024 05:19:05
An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
CVE-2020-26043
- EPSS 0.24%
- Veröffentlicht 30.09.2020 18:15:26
- Zuletzt bearbeitet 21.11.2024 05:19:05
An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php