Known Vulnerabilities for Victor Cms by Victor Cms Project
Listed below are 10 of the newest known vulnerabilities associated with "Victor Cms" by "Victor Cms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34496 json | Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-21655 json | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects vi... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-21653 json | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. T... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2024-24719 json | Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location ... | Not Provided | 2024-03-26 | 2026-04-28 |
| CVE-2022-28060 json | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | 7.5 - HIGH | 2022-04-28 | 2022-05-06 |
| CVE-2022-27478 json | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section... | 8.8 - HIGH | 2022-04-21 | 2022-04-29 |
| CVE-2022-26201 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | 9.8 - CRITICAL | 2022-03-04 | 2022-03-10 |
| CVE-2022-23873 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands vi... | 8.8 - HIGH | 2022-02-03 | 2022-02-08 |
| CVE-2021-46459 json | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_... | 7.5 - HIGH | 2022-01-31 | 2022-02-04 |
| CVE-2021-46458 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. Thi... | 7.5 - HIGH | 2022-01-31 | 2022-02-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Victor Cms Project | Victor Cms | 2019-02-28 | |||
| Application | Victor Cms Project | Victor Cms | 2018-05-10 | |||
| Application | Victor Cms Project | Victor Cms | 1.0 |