Known Vulnerabilities for products from Finecms Project
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Finecms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-1000429 json | rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php. | 6.1 - MEDIUM | 2018-01-09 | 2018-01-26 |
| CVE-2017-14195 json | The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with... | 6.1 - MEDIUM | 2017-09-07 | 2017-09-12 |
| CVE-2017-14194 json | The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Int... | 6.1 - MEDIUM | 2017-09-07 | 2017-09-12 |
| CVE-2017-14193 json | The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Int... | 6.1 - MEDIUM | 2017-09-07 | 2017-09-12 |
| CVE-2017-14192 json | The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field. | 6.1 - MEDIUM | 2017-09-07 | 2017-09-12 |
| CVE-2017-13697 json | controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable. | 6.1 - MEDIUM | 2017-08-25 | 2017-08-29 |
| CVE-2017-12774 json | finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database | 9.8 - CRITICAL | 2017-08-09 | 2017-08-24 |
| CVE-2017-11202 json | FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logg... | Not Provided | 2017-07-13 | 2025-04-20 |
| CVE-2017-11201 json | application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attack... | Not Provided | 2017-07-13 | 2025-04-20 |
| CVE-2017-11200 json | SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter. | Not Provided | 2017-07-13 | 2025-04-20 |
| CVE-2017-11198 json | Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote a... | Not Provided | 2017-07-13 | 2025-04-20 |
| CVE-2017-11180 json | FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Age... | Not Provided | 2017-07-12 | 2025-04-20 |
| CVE-2017-11179 json | FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when register... | Not Provided | 2017-07-12 | 2025-04-20 |
| CVE-2017-11178 json | In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via ... | Not Provided | 2017-07-12 | 2025-04-20 |
| CVE-2017-11167 json | FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this co... | Not Provided | 2017-07-12 | 2025-04-20 |
| CVE-2017-10973 json | In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with ... | Not Provided | 2017-07-06 | 2025-04-20 |
| CVE-2017-10968 json | In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code ... | Not Provided | 2017-07-07 | 2025-04-20 |
| CVE-2017-10967 json | In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) m... | Not Provided | 2017-07-06 | 2025-04-20 |
| CVE-2017-9252 json | andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index... | Not Provided | 2017-05-28 | 2025-04-20 |
| CVE-2017-9251 json | andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php. | Not Provided | 2017-05-28 | 2025-04-20 |
Known software with vulnerabilities from Finecms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Finecms Project | Finecms | - |