Known Vulnerabilities for Luocms by Luocms Project
Listed below are 10 of the newest known vulnerabilities associated with "Luocms" by "Luocms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24609 json | Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attack... | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24608 json | Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | 6.1 - MEDIUM | 2022-03-10 | 2022-03-17 |
| CVE-2022-24607 json | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24606 json | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24605 json | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24604 json | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24603 json | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24602 json | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |
| CVE-2022-24601 json | Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information throug... | 7.5 - HIGH | 2022-03-10 | 2022-03-17 |
| CVE-2022-24600 json | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injec... | 9.8 - CRITICAL | 2022-03-10 | 2022-03-17 |