Known Vulnerabilities for products from Ukcms
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Ukcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-20977 json | A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute ar... | 5.4 - MEDIUM | 2021-08-12 | 2022-09-23 |
| CVE-2020-18449 json | Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php | 5.4 - MEDIUM | 2021-08-12 | 2021-08-13 |
| CVE-2019-10888 json | A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html. | 8.8 - HIGH | 2019-04-05 | 2019-04-07 |
| CVE-2018-14911 json | A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering... | 7.2 - HIGH | 2018-08-03 | 2018-10-10 |
Known software with vulnerabilities from Ukcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Ukcms | Ukcms | 1.0.1 |