Known Vulnerabilities for Tuzicms by Yejiao
Listed below are 5 of the newest known vulnerabilities associated with "Tuzicms" by "Yejiao".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-26301 json | TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiControl... | 9.8 - CRITICAL | 2022-03-24 | 2022-03-29 |
| CVE-2021-44349 json | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.p... | 9.8 - CRITICAL | 2021-12-03 | 2021-12-06 |
| CVE-2021-44348 json | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php. | 9.8 - CRITICAL | 2021-12-03 | 2021-12-06 |
| CVE-2021-44347 json | SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php. | 9.8 - CRITICAL | 2021-12-03 | 2021-12-06 |
| CVE-2019-16642 json | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?i... | 9.8 - CRITICAL | 2019-09-20 | 2019-09-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yejiao | Tuzicms | 2.0.6 |