abocms records
5 published records for vendor abocms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-46953No exploit | SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in the Documents modulabocms · abo.cms · CWE-89 | Critical9.8 | — | 0.8% | Jan 6, 2024 |
39Monitor | CVE-2024-25227Proof of concept | SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escaabocms · abo.cms · CWE-89 | Critical9.8 | — | 0.8% | Mar 15, 2024 |
26Monitor | CVE-2021-37787Proof of concept | The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POSabocms · abo.cms · CWE-89 | Medium6.5 | — | 0.3% | Mar 11, 2025 |
24Monitor | CVE-2023-48858Proof of concept | A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web scripabocms · abo.cms · CWE-79 | Medium6.1 | — | 0.5% | Jan 17, 2024 |
24Monitor | CVE-2023-46952No exploit | Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer headabocms · abo.cms · CWE-79 | Medium6.1 | — | 0.5% | Jan 16, 2024 |
- CVE-2023-4695339Monitor
SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in the Documents modul
CriticalCVSS 9.8No exploitEPSS 1%abocms · abo.cmsJan 6, 2024
- CVE-2024-2522739Monitor
SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), esca
CriticalCVSS 9.8Proof of conceptEPSS 1%abocms · abo.cmsMar 15, 2024
- CVE-2021-3778726Monitor
The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POS
MediumCVSS 6.5Proof of conceptEPSS 0%abocms · abo.cmsMar 11, 2025
- CVE-2023-4885824Monitor
A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web scrip
MediumCVSS 6.1Proof of conceptEPSS 1%abocms · abo.cmsJan 17, 2024
- CVE-2023-4695224Monitor
Cross Site Scripting vulnerability in ABO.CMS v.5.9.3 allows an attacker to execute arbitrary code via a crafted payload to the Referer head
MediumCVSS 6.1No exploitEPSS 0%abocms · abo.cmsJan 16, 2024