Known Vulnerabilities for products from Finecms Project

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Finecms Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2017-1000429 json rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php. 6.1 - MEDIUM 2018-01-09 2018-01-26
CVE-2017-14195 json The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with... 6.1 - MEDIUM 2017-09-07 2017-09-12
CVE-2017-14194 json The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Int... 6.1 - MEDIUM 2017-09-07 2017-09-12
CVE-2017-14193 json The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Int... 6.1 - MEDIUM 2017-09-07 2017-09-12
CVE-2017-14192 json The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field. 6.1 - MEDIUM 2017-09-07 2017-09-12
CVE-2017-13697 json controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable. 6.1 - MEDIUM 2017-08-25 2017-08-29
CVE-2017-12774 json finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database 9.8 - CRITICAL 2017-08-09 2017-08-24
CVE-2017-11202 json FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logg... Not Provided 2017-07-13 2025-04-20
CVE-2017-11201 json application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attack... Not Provided 2017-07-13 2025-04-20
CVE-2017-11200 json SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter. Not Provided 2017-07-13 2025-04-20
CVE-2017-11198 json Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote a... Not Provided 2017-07-13 2025-04-20
CVE-2017-11180 json FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Age... Not Provided 2017-07-12 2025-04-20
CVE-2017-11179 json FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when register... Not Provided 2017-07-12 2025-04-20
CVE-2017-11178 json In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via ... Not Provided 2017-07-12 2025-04-20
CVE-2017-11167 json FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this co... Not Provided 2017-07-12 2025-04-20
CVE-2017-10973 json In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with ... Not Provided 2017-07-06 2025-04-20
CVE-2017-10968 json In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code ... Not Provided 2017-07-07 2025-04-20
CVE-2017-10967 json In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) m... Not Provided 2017-07-06 2025-04-20
CVE-2017-9252 json andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index... Not Provided 2017-05-28 2025-04-20
CVE-2017-9251 json andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php. Not Provided 2017-05-28 2025-04-20

Known software with vulnerabilities from Finecms Project

Type Vendor Product Version
ApplicationFinecms ProjectFinecms-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report