Known Vulnerabilities for products from Ed01-cms Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Ed01-cms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-28525 json | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=... | 8.8 - HIGH | 2022-04-26 | 2022-05-04 |
| CVE-2022-28524 json | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | 9.8 - CRITICAL | 2022-04-26 | 2022-05-04 |
| CVE-2020-18262 json | ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | 9.8 - CRITICAL | 2021-11-03 | 2021-11-05 |
| CVE-2020-18261 json | An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary co... | 9.8 - CRITICAL | 2021-11-03 | 2021-11-05 |
| CVE-2020-18259 json | ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. Th... | 6.1 - MEDIUM | 2021-11-03 | 2021-11-05 |