5none records
12 published records for vendor 5none.
Researcher profile
- Entered KEV
- 1 · 8.3%
- Weaponized
- 1 · 8.3%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- 1058 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2018-20062Weaponized | An issue was discovered in NoneCms V1.3.5none · nonecms | Critical9.8 | KEV | 99.5% | Dec 11, 2018 |
35Monitor | CVE-2018-7219No exploit | application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p5none · nonecms · CWE-352 | High8.8 | — | 0.5% | Feb 19, 2018 |
30Monitor | CVE-2020-18646No exploit | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".5none · nonecms · CWE-668 | High7.5 | — | 1.5% | Jun 22, 2021 |
30Monitor | CVE-2020-18647No exploit | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".5none · nonecms · CWE-668 | High7.5 | — | 1.5% | Jun 22, 2021 |
30Monitor | CVE-2018-6029No exploit | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and5none · nonecms · CWE-918 | High7.5 | — | 1.4% | Jan 23, 2018 |
26Monitor | CVE-2018-6022No exploit | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del5none · nonecms · CWE-22 | Medium6.5 | — | 1.4% | Jan 23, 2018 |
26Monitor | CVE-2019-16721No exploit | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.5none · nonecms · CWE-352 | Medium6.5 | — | 0.5% | Sep 23, 2019 |
24Monitor | CVE-2020-23371No exploit | Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo5none · nonecms · CWE-79 | Medium6.1 | — | 0.9% | May 10, 2021 |
24Monitor | CVE-2020-18282No exploit | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur5none · nonecms · CWE-79 | Medium6.1 | — | 0.5% | May 8, 2023 |
24Monitor | CVE-2020-23376No exploit | NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj5none · nonecms · CWE-352 | Medium6.1 | — | 0.4% | May 10, 2021 |
21Monitor | CVE-2020-23373No exploit | Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w5none · nonecms · CWE-79 | Medium5.4 | — | 0.8% | May 10, 2021 |
21Monitor | CVE-2020-23374No exploit | Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra5none · nonecms · CWE-79 | Medium5.4 | — | 0.8% | May 10, 2021 |
- CVE-2018-2006299Now
An issue was discovered in NoneCms V1.3.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%5none · nonecmsDec 11, 2018
- CVE-2018-721935Monitor
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a p
HighCVSS 8.8No exploitEPSS 1%5none · nonecmsFeb 19, 2018
- CVE-2020-1864630Monitor
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
HighCVSS 7.5No exploitEPSS 2%5none · nonecmsJun 22, 2021
- CVE-2020-1864730Monitor
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
HighCVSS 7.5No exploitEPSS 2%5none · nonecmsJun 22, 2021
- CVE-2018-602930Monitor
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and
HighCVSS 7.5No exploitEPSS 1%5none · nonecmsJan 23, 2018
- CVE-2018-602226Monitor
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to del
MediumCVSS 6.5No exploitEPSS 1%5none · nonecmsJan 23, 2018
- CVE-2019-1672126Monitor
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
MediumCVSS 6.5No exploitEPSS 1%5none · nonecmsSep 23, 2019
- CVE-2020-2337124Monitor
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remo
MediumCVSS 6.1No exploitEPSS 1%5none · nonecmsMay 10, 2021
- CVE-2020-1828224Monitor
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback featur
MediumCVSS 6.1No exploitEPSS 1%5none · nonecmsMay 8, 2023
- CVE-2020-2337624Monitor
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be inj
MediumCVSS 6.1No exploitEPSS 0%5none · nonecmsMay 10, 2021
- CVE-2020-2337321Monitor
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary w
MediumCVSS 5.4No exploitEPSS 1%5none · nonecmsMay 10, 2021
- CVE-2020-2337421Monitor
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitra
MediumCVSS 5.4No exploitEPSS 1%5none · nonecmsMay 10, 2021