Vulnerabilities > Cmseasy

DATE CVE VULNERABILITY TITLE RISK
2025-02-16 CVE-2025-1336 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic.
network
low complexity
cmseasy CWE-22
8.1
2025-02-16 CVE-2025-1335 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9.
network
low complexity
cmseasy CWE-22
8.1
2025-02-07 CVE-2025-1106 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9.
network
low complexity
cmseasy CWE-22
6.5
2025-02-03 CVE-2025-0973 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability classified as critical was found in CmsEasy 7.7.7.9.
network
low complexity
cmseasy CWE-22
6.5
2024-05-07 CVE-2024-34314 Unspecified vulnerability in Cmseasy 7.7.7.9
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php.
network
low complexity
cmseasy
4.9
2024-01-14 CVE-2024-0523 Unspecified vulnerability in Cmseasy
A vulnerability was found in CmsEasy up to 7.7.7.
network
low complexity
cmseasy
critical
9.8
2023-06-27 CVE-2020-18406 Insufficiently Protected Credentials vulnerability in Cmseasy 7.0
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
network
low complexity
cmseasy CWE-522
7.5
2023-06-15 CVE-2023-34880 Path Traversal vulnerability in Cmseasy 7.7.7.7
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php.
network
low complexity
cmseasy CWE-22
critical
9.8
2022-05-17 CVE-2021-42643 Path Traversal vulnerability in Cmseasy 7.7.520211012
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability.
network
low complexity
cmseasy CWE-22
8.8
2022-05-17 CVE-2021-42644 Files or Directories Accessible to External Parties vulnerability in Cmseasy 7.7.520211012
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability.
network
low complexity
cmseasy CWE-552
6.5