8cms records
4 published records for vendor 8cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-20979No exploit | An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.8cms · ljcms · CWE-434 | Critical9.8 | — | 1.6% | Aug 12, 2021 |
39Monitor | CVE-2020-21237No exploit | An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.8cms · ljcms · CWE-307 | Critical9.8 | — | 1.1% | Dec 27, 2021 |
39Monitor | CVE-2020-20735No exploit | File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.8cms · ljcms · CWE-434 | Critical9.8 | — | 1.1% | Jun 20, 2023 |
30Monitor | CVE-2020-20583No exploit | A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.8cms · ljcms · CWE-89 | High7.5 | — | 1.3% | Jul 8, 2021 |
- CVE-2020-2097939Monitor
An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 2%8cms · ljcmsAug 12, 2021
- CVE-2020-2123739Monitor
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
CriticalCVSS 9.8No exploitEPSS 1%8cms · ljcmsDec 27, 2021
- CVE-2020-2073539Monitor
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
CriticalCVSS 9.8No exploitEPSS 1%8cms · ljcmsJun 20, 2023
- CVE-2020-2058330Monitor
A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.
HighCVSS 7.5No exploitEPSS 1%8cms · ljcmsJul 8, 2021