Known Vulnerabilities for products from Monocms
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Monocms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-28672 json | MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/categ... | 7.2 - HIGH | 2021-01-07 | 2021-01-12 |
| CVE-2020-25987 json | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt... | 7.5 - HIGH | 2020-10-06 | 2020-10-07 |
| CVE-2020-25986 json | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. | 6.5 - MEDIUM | 2020-10-06 | 2020-10-14 |
| CVE-2020-25985 json | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (p... | 8.1 - HIGH | 2020-10-07 | 2020-10-07 |
Known software with vulnerabilities from Monocms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Monocms | Monocms | 1.0 |