Skip to content
Noroxi

cxuu records

8 published records for vendor cxuu.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.

    HighCVSS 7.5Proof of conceptEPSS 4%

    cxuu · cxuucmsNov 18, 2020

  • CVE-2021-3264
    28Monitor

    SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.

    HighCVSS 7.2No exploitEPSS 1%

    cxuu · cxuucmsAug 27, 2021

  • CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

    MediumCVSS 6.5No exploitEPSS 0%

    cxuu · cxuucmsDec 26, 2020

  • Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    cxuu · cxuucmsMar 29, 2022

  • CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.

    MediumCVSS 6.1No exploitEPSS 1%

    cxuu · cxuucmsDec 27, 2020

  • CXUUCMS V3 allows class="layui-input" XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    cxuu · cxuucmsDec 27, 2020

  • Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the

    MediumCVSS 6.1No exploitEPSS 1%

    cxuu · cxuucmsAug 23, 2021

  • CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgu

    MediumCVSS 4.8No exploitEPSS 1%

    cxuu · cxuucmsDec 26, 2020