Vulnerabilities > Cmseasy > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-27 CVE-2020-18406 Insufficiently Protected Credentials vulnerability in Cmseasy 7.0
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
network
low complexity
cmseasy CWE-522
7.5
2022-05-17 CVE-2021-42643 Path Traversal vulnerability in Cmseasy 7.7.520211012
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability.
network
low complexity
cmseasy CWE-22
8.8
2018-06-02 CVE-2018-11679 Cross-Site Request Forgery (CSRF) vulnerability in Cmseasy 6.0
An issue was discovered in CmsEasy 6.1_20180508.
network
low complexity
cmseasy CWE-352
8.8