articlecms project records
4 published records for vendor articlecms project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-20092No exploit | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and plaarticlecms project · articlecms · CWE-434 | Critical9.8 | — | 1.3% | May 13, 2021 |
39Monitor | CVE-2020-28063No exploit | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.articlecms project · articlecms · CWE-434 | Critical9.8 | — | 1.3% | May 13, 2021 |
24Monitor | CVE-2018-19469No exploit | ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.articlecms project · articlecms · CWE-79 | Medium6.1 | — | 0.6% | Nov 23, 2018 |
21Monitor | CVE-2018-12339No exploit | ArticleCMS through 2017-02-19 has XSS via an "add an article" action.articlecms project · articlecms · CWE-79 | Medium5.4 | — | 0.5% | Jun 13, 2018 |
- CVE-2020-2009239Monitor
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and pla
CriticalCVSS 9.8No exploitEPSS 1%articlecms project · articlecmsMay 13, 2021
- CVE-2020-2806339Monitor
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
CriticalCVSS 9.8No exploitEPSS 1%articlecms project · articlecmsMay 13, 2021
- CVE-2018-1946924Monitor
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
MediumCVSS 6.1No exploitEPSS 1%articlecms project · articlecmsNov 23, 2018
- CVE-2018-1233921Monitor
ArticleCMS through 2017-02-19 has XSS via an "add an article" action.
MediumCVSS 5.4No exploitEPSS 0%articlecms project · articlecmsJun 13, 2018