CVE-2021-47931
- EPSS 0.21%
- Veröffentlicht 10.05.2026 13:16:29
- Zuletzt bearbeitet 26.05.2026 14:16:25
Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with ...
CVE-2021-32441
- EPSS 0.6%
- Veröffentlicht 17.02.2023 18:15:11
- Zuletzt bearbeitet 19.03.2025 16:15:15
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
CVE-2022-23049
- EPSS 2.99%
- Veröffentlicht 09.02.2022 23:15:19
- Zuletzt bearbeitet 21.11.2024 06:47:53
Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to...
CVE-2022-23048
- EPSS 2.1%
- Veröffentlicht 09.02.2022 23:15:19
- Zuletzt bearbeitet 21.11.2024 06:47:52
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be access...
CVE-2022-23047
- EPSS 2.89%
- Veröffentlicht 09.02.2022 23:15:19
- Zuletzt bearbeitet 21.11.2024 06:47:52
Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_...
CVE-2016-9026
- EPSS 1.28%
- Veröffentlicht 31.12.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 03:00:28
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
CVE-2016-9025
- EPSS 1.25%
- Veröffentlicht 31.12.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 03:00:28
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
CVE-2016-9023
- EPSS 1.25%
- Veröffentlicht 31.12.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 03:00:27
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
CVE-2016-9022
- EPSS 1.28%
- Veröffentlicht 31.12.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 03:00:27
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
CVE-2016-9021
- EPSS 1.28%
- Veröffentlicht 31.12.2020 03:15:12
- Zuletzt bearbeitet 21.11.2024 03:00:27
Exponent CMS before 2.6.0 has improper input validation in storeController.php.