Skip to content
Noroxi

hkcms records

4 published records for vendor hkcms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    hkcms · hkcmsNov 20, 2024

  • HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.

    HighCVSS 7.2No exploitEPSS 0%

    hkcms · hkcmsFeb 27, 2025

  • CVE-2025-5013
    21Monitor

    HkCms Search index.html cross site scripting

    MediumCVSS 5.3No exploitEPSS 1%

    hkcms · hkcmsMay 21, 2025

  • HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.

    MediumCVSS 5.4No exploitEPSS 0%

    hkcms · hkcmsSep 11, 2023