Vulnerabilities > Luocms Project > Luocms > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2022-24609 Incorrect Authorization vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by an incorrect access control vulnerability.
network
low complexity
luocms-project CWE-863
critical
9.8
2022-03-10 CVE-2022-24607 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24606 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24605 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24604 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24603 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24602 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
network
low complexity
luocms-project CWE-89
critical
9.8
2022-03-10 CVE-2022-24600 SQL Injection vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by SQL Injection through /admin/login.php.
network
low complexity
luocms-project CWE-89
critical
9.8