Known Vulnerabilities for products from Impresscms
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Impresscms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-37785 json | A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts ... | 4.8 - MEDIUM | 2023-07-13 | 2023-07-21 |
| CVE-2022-26986 json | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows ... | 7.2 - HIGH | 2022-04-05 | 2023-03-27 |
| CVE-2022-24977 json | ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageNam... | 9.8 - CRITICAL | 2022-02-14 | 2022-02-24 |
| CVE-2021-28088 json | Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject... | 5.4 - MEDIUM | 2021-03-11 | 2021-03-12 |
| CVE-2021-26601 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.1 - HIGH | 2022-03-28 | 2022-03-30 |
| CVE-2021-26600 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-03-28 | 2022-03-30 |
| CVE-2021-26599 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-03-28 | 2022-03-30 |
| CVE-2021-26598 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.3 - MEDIUM | 2022-03-28 | 2022-04-04 |
| CVE-2020-17551 json | ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. | 4.8 - MEDIUM | 2020-10-07 | 2020-10-14 |
| CVE-2019-25703 json | Not Provided | 2026-04-12 | 2026-04-12 | |
| CVE-2018-13983 json | ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/instal... | 6.1 - MEDIUM | 2019-05-06 | 2019-05-07 |
| CVE-2014-4036 json | Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject ... | 4.3 - MEDIUM | 2014-06-11 | 2014-06-12 |
| CVE-2014-1836 json | Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remot... | 6.4 - MEDIUM | 2015-07-01 | 2015-07-02 |
| CVE-2012-0987 json | Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows ... | 6 - MEDIUM | 2012-10-06 | 2017-12-01 |
| CVE-2012-0986 json | Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow... | 4.3 - MEDIUM | 2012-10-06 | 2017-08-29 |
| CVE-2010-4616 json | Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other v... | 4.3 - MEDIUM | 2010-12-29 | 2018-10-10 |
| CVE-2010-4271 json | SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unsp... | 7.5 - HIGH | 2010-11-17 | 2010-11-18 |
| CVE-2008-6360 json | Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allow... | 4.3 - MEDIUM | 2009-03-02 | 2017-08-17 |
| CVE-2008-5964 json | Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by settin... | 6.8 - MEDIUM | 2009-01-23 | 2018-10-11 |
| CVE-2008-3453 json | Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php a... | 10 - HIGH | 2008-08-04 | 2017-08-08 |
Known software with vulnerabilities from Impresscms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Impresscms | Impresscms | 1.0 |