Known Vulnerabilities for products from Tuzicms
Listed below are 7 of the newest known vulnerabilities associated with the vendor "Tuzicms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-46999 json | Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserControlle... | 9.8 - CRITICAL | 2023-01-26 | 2023-02-01 |
| CVE-2022-23882 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-03-28 | 2022-03-31 |
| CVE-2019-16659 json | TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. | 8.8 - HIGH | 2019-09-21 | 2019-09-23 |
| CVE-2019-16658 json | TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. | 8.8 - HIGH | 2019-09-21 | 2019-09-23 |
| CVE-2019-16657 json | TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/. | 6.1 - MEDIUM | 2019-09-21 | 2019-09-23 |
| CVE-2019-16644 json | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substr... | 9.8 - CRITICAL | 2019-09-20 | 2019-09-20 |
| CVE-2018-10185 json | An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a ... | 8.8 - HIGH | 2018-04-17 | 2018-05-21 |
Known software with vulnerabilities from Tuzicms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Tuzicms | Tuzicms | 2.0.6 |