Vulnerabilities > Puppycms

DATE CVE VULNERABILITY TITLE RISK
2022-10-12 CVE-2022-3464 Cross-site Scripting vulnerability in Puppycms 5.1
A vulnerability classified as problematic has been found in puppyCMS up to 5.1.
network
low complexity
puppycms CWE-79
6.1
2021-05-06 CVE-2020-18888 Missing Authorization vulnerability in Puppycms 5.1
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
network
low complexity
puppycms CWE-862
7.5
2021-05-06 CVE-2020-18890 Improper Preservation of Permissions vulnerability in Puppycms 5.1
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
network
low complexity
puppycms CWE-281
critical
9.8
2021-05-06 CVE-2020-18889 Cross-Site Request Forgery (CSRF) vulnerability in Puppycms 5.1
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
network
low complexity
puppycms CWE-352
6.5
2018-08-25 CVE-2018-15847 Cross-site Scripting vulnerability in Puppycms 5.1
An issue was discovered in puppyCMS 5.1.
network
low complexity
puppycms CWE-79
6.1