Vulnerabilities > Sdcms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-11 | CVE-2019-9652 | Cross-Site Request Forgery (CSRF) vulnerability in Sdcms 1.7 There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. | 8.8 |
2019-03-11 | CVE-2019-9651 | Code Injection vulnerability in Sdcms 1.7 An issue was discovered in SDCMS V1.7. | 9.8 |
2018-11-29 | CVE-2018-19748 | Path Traversal vulnerability in Sdcms 1.6 app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&root= directory traversal. | 7.5 |
2018-11-25 | CVE-2018-19520 | Code Injection vulnerability in multiple products An issue was discovered in SDCMS 1.6 with PHP 5.x. | 8.8 |
2018-05-12 | CVE-2018-11004 | Cross-Site Request Forgery (CSRF) vulnerability in Sdcms 1.5 An issue was discovered in SDcms v1.5. | 8.8 |