Vulnerabilities > Elefantcms > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-09-12 CVE-2018-16975 Code Injection vulnerability in Elefantcms Elefant
An issue was discovered in Elefant CMS before 2.0.7.
network
low complexity
elefantcms CWE-94
critical
9.8
2018-09-12 CVE-2018-16974 Unrestricted Upload of File with Dangerous Type vulnerability in Elefantcms Elefant
An issue was discovered in Elefant CMS before 2.0.7.
network
low complexity
elefantcms CWE-434
critical
9.8
2018-08-21 CVE-2018-15601 Improper Input Validation vulnerability in Elefantcms 2.0.3
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism.
network
low complexity
elefantcms CWE-20
critical
9.8