appcms records
6 published records for vendor appcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2020-36005No exploit | AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.appcms · appcms | Medium6.5 | — | 1.1% | Jun 3, 2021 |
26Monitor | CVE-2020-36006No exploit | AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.appcms · appcms | Medium6.5 | — | 1.1% | Jun 3, 2021 |
26Monitor | CVE-2020-36004No exploit | AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database informatioappcms · appcms · CWE-89 | Medium6.5 | — | 0.9% | Jun 3, 2021 |
25Monitor | CVE-2021-45380Proof of concept | AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.phpappcms · appcms · CWE-79 | Medium6.1 | — | 2.5% | Jan 23, 2022 |
24Monitor | CVE-2020-36007No exploit | AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive appcms · appcms · CWE-79 | Medium6.1 | — | 0.9% | Jun 3, 2021 |
24Monitor | CVE-2019-9595No exploit | AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.appcms · appcms · CWE-79 | Medium6.1 | — | 0.8% | Mar 6, 2019 |
- CVE-2020-3600526Monitor
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
MediumCVSS 6.5No exploitEPSS 1%appcms · appcmsJun 3, 2021
- CVE-2020-3600626Monitor
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
MediumCVSS 6.5No exploitEPSS 1%appcms · appcmsJun 3, 2021
- CVE-2020-3600426Monitor
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database informatio
MediumCVSS 6.5No exploitEPSS 1%appcms · appcmsJun 3, 2021
- CVE-2021-4538025Monitor
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
MediumCVSS 6.1Proof of conceptEPSS 3%appcms · appcmsJan 23, 2022
- CVE-2020-3600724Monitor
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive
MediumCVSS 6.1No exploitEPSS 1%appcms · appcmsJun 3, 2021
- CVE-2019-959524Monitor
AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
MediumCVSS 6.1No exploitEPSS 1%appcms · appcmsMar 6, 2019