CVE-2025-14245
- EPSS 0.04%
- Veröffentlicht 08.12.2025 12:32:07
- Zuletzt bearbeitet 11.12.2025 00:07:10
A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulation of the argument params leads to sql injection. The attack may be launched remotely. The exploit h...
CVE-2025-11331
- EPSS 0.16%
- Veröffentlicht 06.10.2025 10:15:34
- Zuletzt bearbeitet 07.10.2025 16:10:55
A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name Handler. Performing manipulation of the argument 网站名称 results in command injection...
CVE-2025-5569
- EPSS 0.58%
- Veröffentlicht 04.06.2025 05:31:51
- Zuletzt bearbeitet 03.10.2025 01:00:36
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be ...
CVE-2025-4291
- EPSS 0.34%
- Veröffentlicht 05.05.2025 22:00:11
- Zuletzt bearbeitet 03.10.2025 14:50:51
A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the...
CVE-2018-16372
- EPSS 0.24%
- Veröffentlicht 03.09.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:37
The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.