74cms records
36 published records for vendor 74cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-552 Files or Directories Accessible to External Parties2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2020-29279Proof of concept | PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 a74cms · 74cms | Critical9.8 | — | 52.9% | Dec 2, 2020 |
42Plan | CVE-2020-22208Proof of concept | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.74cms · 74cms · CWE-89 | Critical9.8 | — | 10.1% | Jun 16, 2021 |
42Plan | CVE-2020-22209Proof of concept | SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.74cms · 74cms · CWE-89 | Critical9.8 | — | 8.6% | Jun 16, 2021 |
42Plan | CVE-2020-22210Proof of concept | SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.74cms · 74cms · CWE-89 | Critical9.8 | — | 8.6% | Jun 16, 2021 |
41Plan | CVE-2020-22211Proof of concept | SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.74cms · 74cms · CWE-89 | Critical9.8 | — | 7.9% | Jun 16, 2021 |
40Plan | CVE-2020-35339No exploit | In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /Thin74cms · 74cms · CWE-94 | Critical9.8 | — | 4.4% | Feb 17, 2021 |
40Plan | CVE-2019-10684No exploit | Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.74cms · 74cms · CWE-94 | Critical9.8 | — | 2.4% | Apr 1, 2019 |
39Monitor | CVE-2020-22212No exploit | SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.74cms · 74cms · CWE-89 | Critical9.8 | — | 1.4% | Jun 16, 2021 |
39Monitor | CVE-2022-42154No exploit | An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary cod74cms · 74cmsse · CWE-434 | Critical9.8 | — | 1.0% | Oct 17, 2022 |
38Monitor | CVE-2019-11374Proof of concept | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.74cms · 74cms · CWE-352 | High8.8 | — | 9.9% | Apr 20, 2019 |
37Monitor | CVE-2024-2561No exploit | 74CMS Company Logo Index.php#sendCompanyLogo unrestricted upload74cms · 74cms · CWE-434 | High8.8 | — | 6.1% | Mar 17, 2024 |
32Monitor | CVE-2018-20519No exploit | An issue was discovered in 74cms v4.2.111.74cms · 74cms · CWE-20 | High8.1 | — | 1.0% | Dec 27, 2018 |
31Monitor | CVE-2022-26271Proof of concept | 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.74cms · 74cms · CWE-552 | High7.5 | — | 4.5% | Mar 27, 2022 |
30Monitor | CVE-2022-33095No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.1% | Jun 23, 2022 |
30Monitor | CVE-2022-29721No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | May 26, 2022 |
30Monitor | CVE-2022-33093No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | Jun 23, 2022 |
30Monitor | CVE-2022-33096No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | Jun 23, 2022 |
30Monitor | CVE-2022-33097No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | Jun 23, 2022 |
30Monitor | CVE-2022-33092No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | Jun 23, 2022 |
30Monitor | CVE-2022-33094No exploit | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.74cms · 74cmsse · CWE-89 | High7.5 | — | 1.0% | Jun 23, 2022 |
30Monitor | CVE-2022-29720No exploit | 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.74cms · 74cmsse · CWE-552 | High7.5 | — | 1.0% | May 26, 2022 |
28Monitor | CVE-2019-17612No exploit | An issue was discovered in 74CMS v5.2.8.74cms · 74cms · CWE-89 | High7.2 | — | 1.0% | Oct 15, 2019 |
26Monitor | CVE-2022-41471No exploit | 74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Admin74cms · 74cmsse | Medium6.5 | — | 0.6% | Oct 17, 2022 |
25Monitor | CVE-2024-46089No exploit | 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.74cms · 74cms · CWE-77 | Medium6.3 | — | 0.6% | Apr 18, 2025 |
24Monitor | CVE-2020-22421No exploit | 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.74cms · 74cms · CWE-79 | Medium6.1 | — | 0.8% | Dec 8, 2021 |
- CVE-2020-2927955Plan
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 a
CriticalCVSS 9.8Proof of conceptEPSS 53%74cms · 74cmsDec 2, 2020
- CVE-2020-2220842Plan
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CriticalCVSS 9.8Proof of conceptEPSS 10%74cms · 74cmsJun 16, 2021
- CVE-2020-2220942Plan
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CriticalCVSS 9.8Proof of conceptEPSS 9%74cms · 74cmsJun 16, 2021
- CVE-2020-2221042Plan
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CriticalCVSS 9.8Proof of conceptEPSS 9%74cms · 74cmsJun 16, 2021
- CVE-2020-2221141Plan
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
CriticalCVSS 9.8Proof of conceptEPSS 8%74cms · 74cmsJun 16, 2021
- CVE-2020-3533940Plan
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /Thin
CriticalCVSS 9.8No exploitEPSS 4%74cms · 74cmsFeb 17, 2021
- CVE-2019-1068440Plan
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.
CriticalCVSS 9.8No exploitEPSS 2%74cms · 74cmsApr 1, 2019
- CVE-2020-2221239Monitor
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
CriticalCVSS 9.8No exploitEPSS 1%74cms · 74cmsJun 16, 2021
- CVE-2022-4215439Monitor
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary cod
CriticalCVSS 9.8No exploitEPSS 1%74cms · 74cmsseOct 17, 2022
- CVE-2019-1137438Monitor
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
HighCVSS 8.8Proof of conceptEPSS 10%74cms · 74cmsApr 20, 2019
- CVE-2024-256137Monitor
74CMS Company Logo Index.php#sendCompanyLogo unrestricted upload
HighCVSS 8.8No exploitEPSS 6%74cms · 74cmsMar 17, 2024
- CVE-2018-2051932Monitor
An issue was discovered in 74cms v4.2.111.
HighCVSS 8.1No exploitEPSS 1%74cms · 74cmsDec 27, 2018
- CVE-2022-2627131Monitor
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
HighCVSS 7.5Proof of conceptEPSS 5%74cms · 74cmsMar 27, 2022
- CVE-2022-3309530Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-2972130Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseMay 26, 2022
- CVE-2022-3309330Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-3309630Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-3309730Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-3309230Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-3309430Monitor
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseJun 23, 2022
- CVE-2022-2972030Monitor
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
HighCVSS 7.5No exploitEPSS 1%74cms · 74cmsseMay 26, 2022
- CVE-2019-1761228Monitor
An issue was discovered in 74CMS v5.2.8.
HighCVSS 7.2No exploitEPSS 1%74cms · 74cmsOct 15, 2019
- CVE-2022-4147126Monitor
74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Admin
MediumCVSS 6.5No exploitEPSS 1%74cms · 74cmsseOct 17, 2022
- CVE-2024-4608925Monitor
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
MediumCVSS 6.3No exploitEPSS 1%74cms · 74cmsApr 18, 2025
- CVE-2020-2242124Monitor
74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.
MediumCVSS 6.1No exploitEPSS 1%74cms · 74cmsDec 8, 2021