Vulnerabilities > Elitecms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-11 | CVE-2022-40361 | Cross-site Scripting vulnerability in Elitecms Elite CMS 1.2.11 Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint. | 6.1 |
2023-09-20 | CVE-2023-42331 | Unrestricted Upload of File with Dangerous Type vulnerability in Elitecms Elite CMS 1.01 A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component. | 8.8 |
2022-06-02 | CVE-2022-30804 | Path Traversal vulnerability in Elitecms Elite CMS 1.01 elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | 6.5 |
2022-06-02 | CVE-2022-30808 | Unrestricted Upload of File with Dangerous Type vulnerability in Elitecms Elite CMS 1.01 elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | 9.8 |
2022-06-02 | CVE-2022-30809 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | 9.8 |
2022-06-02 | CVE-2022-30810 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | 9.8 |
2022-06-02 | CVE-2022-30813 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | 9.8 |
2022-06-02 | CVE-2022-30814 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | 9.8 |
2022-06-02 | CVE-2022-30815 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | 9.8 |
2022-06-02 | CVE-2022-30816 | SQL Injection vulnerability in Elitecms Elite CMS 1.01 elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | 9.8 |