Vulnerabilities > Taogogo > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-24 CVE-2021-34167 Cross-Site Request Forgery (CSRF) vulnerability in Taogogo Taocms 3.0.2
Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.
network
low complexity
taogogo CWE-352
8.8
2022-07-05 CVE-2021-44915 SQL Injection vulnerability in Taogogo Taocms 3.0.2
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
network
low complexity
taogogo CWE-89
7.2
2022-03-01 CVE-2022-23380 SQL Injection vulnerability in Taogogo Taocms 3.0.2
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
network
low complexity
taogogo CWE-89
8.8
2021-12-02 CVE-2021-25783 SQL Injection vulnerability in Taogogo Taocms 2.5
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.
network
low complexity
taogogo CWE-89
7.2
2021-12-02 CVE-2021-25784 SQL Injection vulnerability in Taogogo Taocms 2.5
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.
network
low complexity
taogogo CWE-89
7.2