Vulnerabilities > Rhymix

DATE CVE VULNERABILITY TITLE RISK
2019-01-03 CVE-2018-19601 Server-Side Request Forgery (SSRF) vulnerability in Rhymix 1.9.8.1
Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
network
low complexity
rhymix CWE-918
critical
9.1
2019-01-03 CVE-2018-19600 Cross-site Scripting vulnerability in Rhymix 1.9.8.1
Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.
network
low complexity
rhymix CWE-79
4.8