Записи anchorcms
13 опубликованных записей вендора anchorcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 7,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2018-7251Proof of concept | An issue was discovered in config/error.php in Anchor 0.12.3.anchorcms · anchor · CWE-200 | Критическая9,8 | — | 71,8 % | 19 февр. 2018 г. |
39Наблюдать | CVE-2020-23342Proof of concept | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.anchorcms · anchor cms · CWE-352 | Высокая8,8 | — | 12,4 % | 19 янв. 2021 г. |
31Наблюдать | CVE-2015-5687Эксплойта нет | system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary anchorcms · anchor cms · CWE-94 | Высокая7,5 | — | 2,5 % | 5 окт. 2015 г. |
29Наблюдать | CVE-2024-37732Эксплойта нет | Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.anchorcms · anchor cms · CWE-79 | Средняя6,1 | — | 16,6 % | 24 июн. 2024 г. |
29Наблюдать | CVE-2024-29499Эксплойта нет | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.anchorcms · anchor cms · CWE-352 | Высокая7,4 | — | 0,3 % | 22 мар. 2024 г. |
24Наблюдать | CVE-2021-44116Эксплойта нет | Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php.anchorcms · anchor cms · CWE-79 | Средняя6,1 | — | 0,7 % | 15 дек. 2021 г. |
24Наблюдать | CVE-2015-5060Эксплойта нет | Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.anchorcms · anchor cms · CWE-79 | Средняя6,1 | — | 0,7 % | 7 сент. 2017 г. |
21Наблюдать | CVE-2021-46253Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripanchorcms · anchor cms · CWE-79 | Средняя5,4 | — | 0,6 % | 1 февр. 2022 г. |
21Наблюдать | CVE-2025-46041Proof of concept | A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page descripanchorcms · anchor cms · CWE-79 | Средняя5,4 | — | 0,6 % | 9 июн. 2025 г. |
19Наблюдать | CVE-2020-12071Эксплойта нет | Anchor 0.12.7 allows admins to cause XSS via crafted post content.anchorcms · anchor · CWE-79 | Средняя4,8 | — | 0,6 % | 22 апр. 2020 г. |
18Наблюдать | CVE-2022-25576Эксплойта нет | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php.anchorcms · anchor cms · CWE-352 | Средняя4,5 | — | 0,4 % | 24 мар. 2022 г. |
17Наблюдать | CVE-2014-9182Эксплойта нет | models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Hostanchorcms · anchor cms · CWE-79 | Средняя4,3 | — | 1,0 % | 2 дек. 2014 г. |
9Наблюдать | CVE-2024-29338Эксплойта нет | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.anchorcms · anchor cms · CWE-352 | Низкая2,4 | — | 0,3 % | 22 мар. 2024 г. |
- CVE-2018-725161На этой неделе
An issue was discovered in config/error.php in Anchor 0.12.3.
КритическаяCVSS 9,8Proof of conceptEPSS 72 %anchorcms · anchor19 февр. 2018 г.
- CVE-2020-2334239Наблюдать
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
ВысокаяCVSS 8,8Proof of conceptEPSS 12 %anchorcms · anchor cms19 янв. 2021 г.
- CVE-2015-568731Наблюдать
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %anchorcms · anchor cms5 окт. 2015 г.
- CVE-2024-3773229Наблюдать
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
СредняяCVSS 6,1Эксплойта нетEPSS 17 %anchorcms · anchor cms24 июн. 2024 г.
- CVE-2024-2949929Наблюдать
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %anchorcms · anchor cms22 мар. 2024 г.
- CVE-2021-4411624Наблюдать
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %anchorcms · anchor cms15 дек. 2021 г.
- CVE-2015-506024Наблюдать
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %anchorcms · anchor cms7 сент. 2017 г.
- CVE-2021-4625321Наблюдать
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scrip
СредняяCVSS 5,4Эксплойта нетEPSS 1 %anchorcms · anchor cms1 февр. 2022 г.
- CVE-2025-4604121Наблюдать
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page descrip
СредняяCVSS 5,4Proof of conceptEPSS 1 %anchorcms · anchor cms9 июн. 2025 г.
- CVE-2020-1207119Наблюдать
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %anchorcms · anchor22 апр. 2020 г.
- CVE-2022-2557618Наблюдать
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php.
СредняяCVSS 4,5Эксплойта нетEPSS 0 %anchorcms · anchor cms24 мар. 2022 г.
- CVE-2014-918217Наблюдать
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host
СредняяCVSS 4,3Эксплойта нетEPSS 1 %anchorcms · anchor cms2 дек. 2014 г.
- CVE-2024-293389Наблюдать
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.
НизкаяCVSS 2,4Эксплойта нетEPSS 0 %anchorcms · anchor cms22 мар. 2024 г.