Known Vulnerabilities for products from Easycms
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Easycms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-3786 json | A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAc... | Not Provided | 2026-03-08 | 2026-04-29 |
| CVE-2026-3785 json | A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.... | Not Provided | 2026-03-08 | 2026-04-29 |
| CVE-2026-1105 json | A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.ph... | Not Provided | 2026-01-18 | 2026-04-29 |
| CVE-2022-23358 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-02-16 | 2022-02-23 |
| CVE-2020-24271 json | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/... | 8.8 - HIGH | 2021-02-01 | 2021-02-05 |
| CVE-2019-6294 json | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbac... | 8.8 - HIGH | 2019-01-15 | 2019-01-16 |
| CVE-2018-17113 json | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieN... | 6.1 - MEDIUM | 2018-09-17 | 2018-11-09 |
| CVE-2018-16773 json | EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field. | 4.8 - MEDIUM | 2018-09-10 | 2018-09-24 |
| CVE-2018-16759 json | The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4... | 6.1 - MEDIUM | 2018-09-09 | 2018-11-07 |
| CVE-2018-16345 json | An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/adm... | 8.8 - HIGH | 2018-09-02 | 2018-11-13 |
| CVE-2018-12971 json | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. | 6.5 - MEDIUM | 2018-06-29 | 2018-08-20 |
| CVE-2018-10374 json | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request. | 6.1 - MEDIUM | 2018-04-25 | 2018-05-23 |
Known software with vulnerabilities from Easycms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Easycms | Easycms | 1.0 |