Known Vulnerabilities for Cutenews by Cutephp
Listed below are 10 of the newest known vulnerabilities associated with "Cutenews" by "Cutephp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-36472 json | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a r... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-36471 json | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker... | Not Provided | 2026-09-21 | 2026-09-25 |
| CVE-2026-36470 json | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into t... | Not Provided | 2026-09-21 | 2026-09-22 |
| CVE-2026-36469 json | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Man... | Not Provided | 2026-09-21 | 2026-09-24 |
| CVE-2026-36468 json | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-36467 json | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated use... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2020-5558 json | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. | 8.8 - HIGH | 2020-03-25 | 2021-07-21 |
| CVE-2020-5557 json | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspe... | 6.1 - MEDIUM | 2020-03-25 | 2020-03-26 |
| CVE-2019-11447 json | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in... | 8.8 - HIGH | 2019-04-22 | 2020-09-11 |
| CVE-2009-4250 json | Not Provided | 2009-12-10 | 2026-04-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cutephp | Cutenews | 2.1.2 | |||
| Application | Cutephp | Cutenews | 2.1.1 | |||
| Application | Cutephp | Cutenews | 2.1.0 | |||
| Application | Cutephp | Cutenews | 2.0.4 | |||
| Application | Cutephp | Cutenews | 2.0.3 | |||
| Application | Cutephp | Cutenews | 2.0.2 | |||
| Application | Cutephp | Cutenews | 2.0.1 | |||
| Application | Cutephp | Cutenews | 2.0.0 | |||
| Application | Cutephp | Cutenews | 1.5.3 | |||
| Application | Cutephp | Cutenews | 1.5.2 | |||
| Application | Cutephp | Cutenews | 1.5.1 | |||
| Application | Cutephp | Cutenews | 1.5.0.7 | |||
| Application | Cutephp | Cutenews | 1.5.0.6 | |||
| Application | Cutephp | Cutenews | 1.5.0.5 | |||
| Application | Cutephp | Cutenews | 1.5.0.4 | |||
| Application | Cutephp | Cutenews | 1.5.0.3 | |||
| Application | Cutephp | Cutenews | 1.5.0.2 | |||
| Application | Cutephp | Cutenews | 1.5.0.1 |