Vulnerabilities > Elefantcms

DATE CVE VULNERABILITY TITLE RISK
2018-09-03 CVE-2018-16387 Cross-Site Request Forgery (CSRF) vulnerability in Elefantcms
An issue was discovered in Elefant CMS before 2.0.5.
network
low complexity
elefantcms CWE-352
8.8
2018-08-21 CVE-2018-15601 Improper Input Validation vulnerability in Elefantcms 2.0.3
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism.
network
low complexity
elefantcms CWE-20
critical
9.8