Known Vulnerabilities for products from Finecms
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Finecms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-18191 json | Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attac... | 8.8 - HIGH | 2018-10-09 | 2018-11-21 |
| CVE-2018-7476 json | controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=linka... | 6.1 - MEDIUM | 2018-02-25 | 2018-03-16 |
| CVE-2018-6893 json | controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and the par... | 9.8 - CRITICAL | 2018-02-12 | 2018-03-06 |
| CVE-2017-16920 json | v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each insta... | Not Provided | 2017-11-21 | 2025-04-20 |
| CVE-2017-16866 json | dayrui FineCms 5.2.0 before 2017.11.16 has Cross Site Scripting (XSS) in core/M_Controller.php via the DR_URI field. | Not Provided | 2017-11-16 | 2025-04-20 |
| CVE-2017-11629 json | dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=api&m=d... | Not Provided | 2017-07-26 | 2025-04-20 |
| CVE-2017-11586 json | dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php. | Not Provided | 2017-07-24 | 2025-04-20 |
| CVE-2017-11585 json | dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.p... | Not Provided | 2017-07-24 | 2025-04-20 |
| CVE-2017-11584 json | dayrui FineCms 5.0.9 has SQL Injection via the field parameter in an action=module, action=member, action=form, or action=rel... | Not Provided | 2017-07-24 | 2025-04-20 |
| CVE-2017-11583 json | dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php. | Not Provided | 2017-07-24 | 2025-04-20 |
| CVE-2017-11582 json | dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Templat... | Not Provided | 2017-07-24 | 2025-04-20 |
| CVE-2017-11581 json | dayrui FineCms 5.0.9 has Cross Site Scripting (XSS) in admin/Login.php via a payload in the username field that does not begi... | Not Provided | 2017-07-24 | 2025-04-20 |
Known software with vulnerabilities from Finecms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Finecms | Finecms | 1.9.5 |