Schlix

Cms

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 16.01.2026 19:16:08
  • Zuletzt bearbeitet 26.01.2026 15:05:57

Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the...

  • EPSS 0.04%
  • Veröffentlicht 22.12.2025 00:00:00
  • Zuletzt bearbeitet 02.01.2026 16:56:19

Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.

Exploit
  • EPSS 0.97%
  • Veröffentlicht 31.01.2024 03:15:08
  • Zuletzt bearbeitet 21.11.2024 08:01:59

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

Exploit
  • EPSS 4.32%
  • Veröffentlicht 07.02.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 07:29:25

Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to u...

  • EPSS 3.1%
  • Veröffentlicht 24.10.2019 16:15:20
  • Zuletzt bearbeitet 21.11.2024 04:20:22

admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin...