Known Vulnerabilities for products from Auracms

Listed below are 18 of the newest known vulnerabilities associated with the vendor "Auracms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2018-16338 json An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.... 8.8 - HIGH 2018-09-02 2018-10-25
CVE-2018-15199 json AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action. 5.4 - MEDIUM 2018-08-08 2018-10-04
CVE-2014-3975 json Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a ful... Not Provided 2014-06-05 2026-05-06
CVE-2014-3974 json Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbi... Not Provided 2014-06-05 2026-05-06
CVE-2014-1401 json Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL c... Not Provided 2014-02-11 2026-04-29
CVE-2010-4774 json SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id p... Not Provided 2011-03-23 2026-04-29
CVE-2008-3203 json js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, e... Not Provided 2008-07-17 2026-04-23
CVE-2008-1715 json SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remot... Not Provided 2008-04-09 2026-04-23
CVE-2008-1398 json SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL comma... Not Provided 2008-03-20 2026-04-23
CVE-2008-0811 json Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the k... Not Provided 2008-02-19 2026-04-23
CVE-2008-0735 json SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary ... Not Provided 2008-02-13 2026-04-23
CVE-2008-0390 json stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into onli... Not Provided 2008-01-23 2026-04-23
CVE-2007-6552 json Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitr... Not Provided 2007-12-28 2026-04-23
CVE-2007-4908 json Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbi... Not Provided 2007-09-17 2026-04-23
CVE-2007-4905 json Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitra... Not Provided 2007-09-17 2026-04-23
CVE-2007-4886 json Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary ... Not Provided 2007-09-14 2026-04-23
CVE-2007-4804 json Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id p... Not Provided 2007-09-11 2026-04-23
CVE-2007-4171 json SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers t... Not Provided 2007-08-07 2026-04-23

Known software with vulnerabilities from Auracms

Type Vendor Product Version
ApplicationAuracmsAuracms3.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report