Vulnerabilities > Chemcms Project

DATE CVE VULNERABILITY TITLE RISK
2018-09-02 CVE-2018-16346 Cross-site Scripting vulnerability in Chemcms Project Chemcms 1.0.6
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
network
low complexity
chemcms-project CWE-79
4.8
2018-04-22 CVE-2018-10295 Cross-Site Request Forgery (CSRF) vulnerability in Chemcms Project Chemcms 1.0.6
ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.
network
low complexity
chemcms-project CWE-352
8.8