catfish-cms records
9 published records for vendor catfish-cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-18735No exploit | A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.catfish-cms · catfish blog · CWE-352 | High8.8 | — | 0.5% | Oct 29, 2018 |
35Monitor | CVE-2018-18734No exploit | A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.catfish-cms · catfish cms · CWE-352 | High8.8 | — | 0.5% | Oct 29, 2018 |
35Monitor | CVE-2021-45017No exploit | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uscatfish-cms · catfish cms · CWE-352 | High8.8 | — | 0.4% | Dec 15, 2021 |
24Monitor | CVE-2020-23962No exploit | A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted paycatfish-cms · catfish cms · CWE-79 | Medium6.1 | — | 0.7% | Jun 23, 2021 |
24Monitor | CVE-2021-45018No exploit | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmlcatfish-cms · catfish cms · CWE-79 | Medium6.1 | — | 0.6% | Dec 15, 2021 |
21Monitor | CVE-2018-10023No exploit | Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).catfish-cms · catfish cms · CWE-79 | Medium5.4 | — | 0.6% | Apr 11, 2018 |
21Monitor | CVE-2018-18736No exploit | An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."catfish-cms · catfish blog · CWE-79 | Medium5.4 | — | 0.6% | Oct 29, 2018 |
21Monitor | CVE-2018-18733No exploit | An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.catfish-cms · catfish cms · CWE-79 | Medium5.4 | — | 0.5% | Oct 29, 2018 |
19Monitor | CVE-2018-13999No exploit | Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).catfish-cms · catfish cms · CWE-79 | Medium4.8 | — | 0.5% | Jul 12, 2018 |
- CVE-2018-1873535Monitor
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
HighCVSS 8.8No exploitEPSS 1%catfish-cms · catfish blogOct 29, 2018
- CVE-2018-1873435Monitor
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
HighCVSS 8.8No exploitEPSS 0%catfish-cms · catfish cmsOct 29, 2018
- CVE-2021-4501735Monitor
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that us
HighCVSS 8.8No exploitEPSS 0%catfish-cms · catfish cmsDec 15, 2021
- CVE-2020-2396224Monitor
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted pay
MediumCVSS 6.1No exploitEPSS 1%catfish-cms · catfish cmsJun 23, 2021
- CVE-2021-4501824Monitor
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.html
MediumCVSS 6.1No exploitEPSS 1%catfish-cms · catfish cmsDec 15, 2021
- CVE-2018-1002321Monitor
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
MediumCVSS 5.4No exploitEPSS 1%catfish-cms · catfish cmsApr 11, 2018
- CVE-2018-1873621Monitor
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
MediumCVSS 5.4No exploitEPSS 1%catfish-cms · catfish blogOct 29, 2018
- CVE-2018-1873321Monitor
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
MediumCVSS 5.4No exploitEPSS 1%catfish-cms · catfish cmsOct 29, 2018
- CVE-2018-1399919Monitor
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).
MediumCVSS 4.8No exploitEPSS 1%catfish-cms · catfish cmsJul 12, 2018