Known Vulnerabilities for products from Genixcms
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Genixcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-17431 json | GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap... | Not Provided | 2017-12-05 | 2025-04-20 |
| CVE-2017-14765 json | In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request. | 6.1 - MEDIUM | 2017-09-27 | 2017-09-29 |
| CVE-2017-14764 json | In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ... | 8.8 - HIGH | 2017-09-27 | 2017-09-29 |
| CVE-2017-14763 json | In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ... | 8.8 - HIGH | 2017-09-27 | 2019-10-03 |
| CVE-2017-14762 json | In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter. | 6.1 - MEDIUM | 2017-09-27 | 2017-09-29 |
| CVE-2017-14761 json | In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter. | 6.1 - MEDIUM | 2017-09-27 | 2017-09-29 |
| CVE-2017-14740 json | Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script o... | 4.8 - MEDIUM | 2018-04-26 | 2018-05-25 |
| CVE-2017-14231 json | GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling o... | 5.3 - MEDIUM | 2017-09-10 | 2017-09-19 |
| CVE-2017-8827 json | forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (log... | Not Provided | 2017-05-08 | 2025-04-20 |
| CVE-2017-8780 json | GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstra... | Not Provided | 2017-05-04 | 2025-04-20 |
| CVE-2017-8762 json | GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in... | Not Provided | 2017-05-03 | 2025-04-20 |
| CVE-2017-8388 json | GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php... | Not Provided | 2017-05-01 | 2025-04-20 |
| CVE-2017-8377 json | GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter. | Not Provided | 2017-05-01 | 2025-04-20 |
| CVE-2017-8376 json | GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator. | Not Provided | 2017-05-01 | 2025-04-20 |
| CVE-2017-5346 json | SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated admini... | Not Provided | 2017-01-12 | 2026-05-06 |
| CVE-2016-10096 json | SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL command... | Not Provided | 2017-01-01 | 2026-05-06 |
| CVE-2015-2679 json | Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL co... | Not Provided | 2015-03-23 | 2026-05-06 |
| CVE-2015-2678 json | Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbi... | Not Provided | 2015-03-23 | 2026-05-06 |
Known software with vulnerabilities from Genixcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Genixcms | Genixcms | 0.0.1 |