Known Vulnerabilities for products from S-cms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "S-cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-29963 json | S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax... | 7.2 - HIGH | 2023-05-05 | 2023-05-11 |
| CVE-2023-29962 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2024-01-04 | 2024-01-10 |
| CVE-2023-7191 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-31 | 2024-01-05 |
| CVE-2023-7190 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-31 | 2024-01-05 |
| CVE-2023-7189 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-31 | 2024-01-05 |
| CVE-2022-23336 json | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. | 9.8 - CRITICAL | 2022-02-14 | 2022-02-22 |
| CVE-2022-4377 json | A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is... | 5.4 - MEDIUM | 2022-12-09 | 2023-11-07 |
| CVE-2021-37270 json | There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this v... | 9.8 - CRITICAL | 2021-09-27 | 2021-10-06 |
| CVE-2020-20701 json | A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web ... | 4.8 - MEDIUM | 2021-07-30 | 2021-08-03 |
| CVE-2020-20700 json | A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary we... | 4.8 - MEDIUM | 2021-07-30 | 2021-08-03 |
| CVE-2020-20699 json | A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a ... | 4.8 - MEDIUM | 2021-07-30 | 2021-08-03 |
| CVE-2020-20698 json | A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of ... | 7.2 - HIGH | 2021-07-30 | 2021-08-05 |
| CVE-2020-20426 json | S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php. | Not Provided | 2021-12-22 | 2026-07-09 |
| CVE-2020-20425 json | S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function. | Not Provided | 2021-12-22 | 2026-07-09 |
| CVE-2020-20340 json | A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive... | 7.5 - HIGH | 2021-09-01 | 2021-09-10 |
| CVE-2020-19954 json | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbi... | 7.5 - HIGH | 2021-10-14 | 2021-10-20 |
| CVE-2020-19158 json | Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Sit... | 5.4 - MEDIUM | 2021-09-15 | 2021-09-22 |
| CVE-2020-19046 json | Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?... | 5.4 - MEDIUM | 2021-08-31 | 2021-09-07 |
| CVE-2019-17368 json | S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. | 6.1 - MEDIUM | 2019-10-09 | 2019-10-09 |
| CVE-2019-16312 json | s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. | 6.1 - MEDIUM | 2019-09-14 | 2019-09-16 |
Known software with vulnerabilities from S-cms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | S-cms | S-cms | 1.0 |