CVE-2020-18282
- EPSS 0.04%
- Published 08.05.2023 14:15:10
- Last modified 29.01.2025 17:15:10
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.
CVE-2020-18647
- EPSS 0.23%
- Published 22.06.2021 15:15:11
- Last modified 21.11.2024 05:08:39
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
CVE-2020-18646
- EPSS 0.23%
- Published 22.06.2021 15:15:10
- Last modified 21.11.2024 05:08:39
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
CVE-2020-23371
- EPSS 0.19%
- Published 10.05.2021 23:15:07
- Last modified 21.11.2024 05:13:47
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
CVE-2020-23373
- EPSS 0.13%
- Published 10.05.2021 23:15:07
- Last modified 21.11.2024 05:13:47
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
CVE-2020-23374
- EPSS 0.13%
- Published 10.05.2021 23:15:07
- Last modified 21.11.2024 05:13:48
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
CVE-2020-23376
- EPSS 0.14%
- Published 10.05.2021 23:15:07
- Last modified 21.11.2024 05:13:48
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.
CVE-2019-16721
- EPSS 0.12%
- Published 23.09.2019 14:15:10
- Last modified 21.11.2024 04:31:03
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
CVE-2018-20062
- EPSS 94.31%
- Published 11.12.2018 18:29:00
- Last modified 07.03.2025 14:22:47
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query str...
CVE-2018-7219
- EPSS 0.13%
- Published 19.02.2018 14:29:00
- Last modified 21.11.2024 04:11:49
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.