CVE-2021-47834
- EPSS 0.01%
- Veröffentlicht 16.01.2026 19:16:08
- Zuletzt bearbeitet 26.01.2026 15:05:57
Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the...
CVE-2025-67443
- EPSS 0.04%
- Veröffentlicht 22.12.2025 00:00:00
- Zuletzt bearbeitet 02.01.2026 16:56:19
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.
CVE-2023-31505
- EPSS 0.97%
- Veröffentlicht 31.01.2024 03:15:08
- Zuletzt bearbeitet 21.11.2024 08:01:59
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.
CVE-2022-45544
- EPSS 4.32%
- Veröffentlicht 07.02.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:29:25
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to u...
CVE-2019-11021
- EPSS 3.1%
- Veröffentlicht 24.10.2019 16:15:20
- Zuletzt bearbeitet 21.11.2024 04:20:22
admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin...