Known Vulnerabilities for products from 74cms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "74cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42154 json | An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execut... | 9.8 - CRITICAL | 2022-10-17 | 2022-10-19 |
| CVE-2022-41472 json | 74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. ... | 5.4 - MEDIUM | 2022-10-17 | 2022-10-29 |
| CVE-2022-41471 json | 74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of ... | 6.5 - MEDIUM | 2022-10-17 | 2023-08-08 |
| CVE-2022-33097 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job. | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33096 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33095 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelis... | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33094 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33093 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33092 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. | 7.5 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-32131 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/sho... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32130 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_res... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32129 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32128 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32127 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32126 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company. | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32125 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-32124 json | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfa... | 6.1 - MEDIUM | 2022-06-23 | 2022-06-29 |
| CVE-2022-29721 json | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelis... | 7.5 - HIGH | 2022-05-26 | 2022-05-31 |
| CVE-2022-29720 json | 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.ph... | 7.5 - HIGH | 2022-05-26 | 2022-06-03 |
| CVE-2022-26271 json | 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Dow... | 7.5 - HIGH | 2022-03-28 | 2022-03-31 |
Known software with vulnerabilities from 74cms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | 74cms | 74cms | 4.2.111 |