Known Vulnerabilities for Cxuucms by Cxuu
Listed below are 8 of the newest known vulnerabilities associated with "Cxuucms" by "Cxuu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-42970 json | Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. | 6.1 - MEDIUM | 2022-03-29 | 2022-04-04 |
| CVE-2021-39599 json | Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search... | 6.1 - MEDIUM | 2021-08-23 | 2021-08-30 |
| CVE-2021-3264 json | SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. | 7.2 - HIGH | 2021-08-27 | 2021-09-01 |
| CVE-2020-35347 json | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. | 6.5 - MEDIUM | 2020-12-26 | 2020-12-28 |
| CVE-2020-35346 json | CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HT... | 4.8 - MEDIUM | 2020-12-26 | 2020-12-28 |
| CVE-2020-29250 json | CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. | 6.1 - MEDIUM | 2020-12-27 | 2020-12-29 |
| CVE-2020-29249 json | CXUUCMS V3 allows class="layui-input" XSS. | 6.1 - MEDIUM | 2020-12-27 | 2020-12-29 |
| CVE-2020-28091 json | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter v... | 7.5 - HIGH | 2020-11-18 | 2020-12-01 |