Known Vulnerabilities for products from Razorcms
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Razorcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-19906 json | Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. | 5.4 - MEDIUM | 2018-12-31 | 2019-02-25 |
| CVE-2018-19905 json | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. | 5.4 - MEDIUM | 2018-12-31 | 2019-02-26 |
| CVE-2018-17986 json | rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user. | 8.8 - HIGH | 2018-10-05 | 2018-11-27 |
| CVE-2018-16727 json | razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | 5.4 - MEDIUM | 2018-09-12 | 2018-11-02 |
| CVE-2018-16726 json | razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. | 5.4 - MEDIUM | 2018-09-12 | 2018-11-02 |
| CVE-2012-6038 json | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and... | Not Provided | 2012-11-26 | 2026-04-29 |
| CVE-2012-5918 json | razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a direc... | Not Provided | 2012-11-19 | 2026-04-29 |
| CVE-2012-1900 json | Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to h... | Not Provided | 2012-10-22 | 2026-04-29 |
| CVE-2010-5051 json | Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to injec... | Not Provided | 2011-11-23 | 2026-04-29 |
| CVE-2009-1463 json | Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page... | Not Provided | 2009-04-28 | 2026-04-23 |
| CVE-2009-1462 json | The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, w... | Not Provided | 2009-04-28 | 2026-04-23 |
| CVE-2009-1461 json | Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authentica... | Not Provided | 2009-04-28 | 2026-04-23 |
| CVE-2009-1460 json | razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the adminis... | Not Provided | 2009-04-28 | 2026-04-23 |
| CVE-2009-1459 json | Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication o... | Not Provided | 2009-04-28 | 2026-04-23 |
| CVE-2009-1458 json | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to injec... | Not Provided | 2009-04-28 | 2026-04-23 |
Known software with vulnerabilities from Razorcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Razorcms | Razorcms | 0.2 |