Known Vulnerabilities for Victor Cms by Victor Cms Project
Listed below are 10 of the newest known vulnerabilities associated with "Victor Cms" by "Victor Cms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-24719 json | Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location ... | Not Provided | 2024-03-26 | 2026-04-28 |
| CVE-2022-28060 json | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | 7.5 - HIGH | 2022-04-28 | 2022-05-06 |
| CVE-2022-27478 json | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section... | 8.8 - HIGH | 2022-04-21 | 2022-04-29 |
| CVE-2022-26201 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | 9.8 - CRITICAL | 2022-03-04 | 2022-03-10 |
| CVE-2022-23873 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands vi... | 8.8 - HIGH | 2022-02-03 | 2022-02-08 |
| CVE-2021-46459 json | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_... | 7.5 - HIGH | 2022-01-31 | 2022-02-04 |
| CVE-2021-46458 json | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. Thi... | 7.5 - HIGH | 2022-01-31 | 2022-02-19 |
| CVE-2021-25203 json | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CM... | 9.8 - CRITICAL | 2021-07-23 | 2021-07-29 |
| CVE-2020-35597 json | Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post... | 8.8 - HIGH | 2022-06-16 | 2022-06-27 |
| CVE-2020-29280 json | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. | 9.8 - CRITICAL | 2020-12-02 | 2020-12-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Victor Cms Project | Victor Cms | 2019-02-28 | |||
| Application | Victor Cms Project | Victor Cms | 2018-05-10 | |||
| Application | Victor Cms Project | Victor Cms | 1.0 |