Known Vulnerabilities for Hongcms by Hongcms Project
Listed below are 10 of the newest known vulnerabilities associated with "Hongcms" by "Hongcms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-32412 json | An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell. | 7.2 - HIGH | 2022-07-01 | 2022-07-13 |
| CVE-2022-32411 json | An issue in the languages config file of HongCMS v3.0 allows attackers to getshell. | 7.2 - HIGH | 2022-07-01 | 2022-07-13 |
| CVE-2022-28523 json | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | 8.1 - HIGH | 2022-04-26 | 2022-05-05 |
| CVE-2020-21643 json | Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to ... | 6.1 - MEDIUM | 2023-04-28 | 2023-05-05 |
| CVE-2020-21431 json | HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit. | 6.5 - MEDIUM | 2021-10-04 | 2021-10-13 |
| CVE-2020-21252 json | Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escala... | 8.8 - HIGH | 2023-06-20 | 2023-06-27 |
| CVE-2020-18178 json | Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request... | 9.8 - CRITICAL | 2021-05-18 | 2021-05-24 |
| CVE-2019-17611 json | HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter. | 6.1 - MEDIUM | 2019-10-16 | 2019-10-18 |
| CVE-2019-17610 json | HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter. | 6.1 - MEDIUM | 2019-10-16 | 2019-10-18 |
| CVE-2019-17609 json | HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter. | 6.1 - MEDIUM | 2019-10-16 | 2019-10-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hongcms Project | Hongcms | 3.0.0 |