Known Vulnerabilities for products from Catfish-cms
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Catfish-cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-45018 json | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Ind... | 6.1 - MEDIUM | 2021-12-15 | 2021-12-20 |
| CVE-2021-45017 json | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the ... | 8.8 - HIGH | 2021-12-15 | 2021-12-20 |
| CVE-2020-23962 json | A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML vi... | 6.1 - MEDIUM | 2021-06-23 | 2021-06-28 |
| CVE-2018-18736 json | An XSS issue was discovered in catfish blog 2.0.33, related to "write source code." | 5.4 - MEDIUM | 2018-10-29 | 2018-12-07 |
| CVE-2018-18735 json | A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | 8.8 - HIGH | 2018-10-29 | 2018-11-14 |
| CVE-2018-18734 json | A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30. | 8.8 - HIGH | 2018-10-29 | 2018-11-13 |
| CVE-2018-18733 json | An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999. | 5.4 - MEDIUM | 2018-10-29 | 2018-12-07 |
| CVE-2018-13999 json | Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator... | 4.8 - MEDIUM | 2018-07-12 | 2018-09-04 |
| CVE-2018-10023 json | Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). | 5.4 - MEDIUM | 2018-04-11 | 2021-10-01 |
Known software with vulnerabilities from Catfish-cms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Catfish-cms | Catfish-cms | 4.7.21 |
| Application | Catfish-cms | Catfish Blog | 2.0.33 |
| Application | Catfish-cms | Catfish Cms | 4.7.9 |