Skip to content
Noroxi

74cms records

36 published records for vendor 74cms.

All records

36 records
  • PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 a

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    74cms · 74cmsDec 2, 2020

  • SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    74cms · 74cmsJun 16, 2021

  • SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    74cms · 74cmsJun 16, 2021

  • SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    74cms · 74cmsJun 16, 2021

  • SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    74cms · 74cmsJun 16, 2021

  • In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /Thin

    CriticalCVSS 9.8No exploitEPSS 4%

    74cms · 74cmsFeb 17, 2021

  • Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.

    CriticalCVSS 9.8No exploitEPSS 2%

    74cms · 74cmsApr 1, 2019

  • SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    74cms · 74cmsJun 16, 2021

  • An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary cod

    CriticalCVSS 9.8No exploitEPSS 1%

    74cms · 74cmsseOct 17, 2022

  • 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

    HighCVSS 8.8Proof of conceptEPSS 10%

    74cms · 74cmsApr 20, 2019

  • CVE-2024-2561
    37Monitor

    74CMS Company Logo Index.php#sendCompanyLogo unrestricted upload

    HighCVSS 8.8No exploitEPSS 6%

    74cms · 74cmsMar 17, 2024

  • An issue was discovered in 74cms v4.2.111.

    HighCVSS 8.1No exploitEPSS 1%

    74cms · 74cmsDec 27, 2018

  • 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

    HighCVSS 7.5Proof of conceptEPSS 5%

    74cms · 74cmsMar 27, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseMay 26, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseJun 23, 2022

  • 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.

    HighCVSS 7.5No exploitEPSS 1%

    74cms · 74cmsseMay 26, 2022

  • An issue was discovered in 74CMS v5.2.8.

    HighCVSS 7.2No exploitEPSS 1%

    74cms · 74cmsOct 15, 2019

  • 74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Admin

    MediumCVSS 6.5No exploitEPSS 1%

    74cms · 74cmsseOct 17, 2022

  • 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

    MediumCVSS 6.3No exploitEPSS 1%

    74cms · 74cmsApr 18, 2025

  • 74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.

    MediumCVSS 6.1No exploitEPSS 1%

    74cms · 74cmsDec 8, 2021