classcms records
8 published records for vendor classcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-266 Incorrect Privilege Assignment1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-57099No exploit | ClassCMS v4.8 has a code execution vulnerability.classcms · classcms · CWE-94 | Critical9.8 | — | 0.7% | Feb 3, 2025 |
39Monitor | CVE-2024-48180No exploit | ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/teclasscms · classcms · CWE-434 | Critical9.8 | — | 0.6% | Oct 16, 2024 |
31Monitor | CVE-2022-25581Proof of concept | Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload.classcms · classcms · CWE-434 | High7.8 | — | 1.2% | Mar 18, 2022 |
21Monitor | CVE-2024-8144No exploit | ClassCMS Logo admin cross site scriptingclasscms · classcms · CWE-79 | Medium5.3 | — | 0.4% | Aug 25, 2024 |
20Monitor | CVE-2024-12503No exploit | ClassCMS Model Management Page admin cross site scriptingclasscms · classcms · CWE-79 | Medium5.1 | — | 0.5% | Dec 11, 2024 |
20Monitor | CVE-2024-12666No exploit | ClassCMS User Management Page admin insufficient privilegesclasscms · classcms · CWE-266 | Medium5.1 | — | 0.5% | Dec 16, 2024 |
20Monitor | CVE-2024-8145No exploit | ClassCMS Article admin cross site scriptingclasscms · classcms · CWE-80 | Medium5.1 | — | 0.4% | Aug 25, 2024 |
19Monitor | CVE-2024-57097No exploit | ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.classcms · classcms · CWE-79 | Medium4.8 | — | 0.2% | Feb 3, 2025 |
- CVE-2024-5709939Monitor
ClassCMS v4.8 has a code execution vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%classcms · classcmsFeb 3, 2025
- CVE-2024-4818039Monitor
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/te
CriticalCVSS 9.8No exploitEPSS 1%classcms · classcmsOct 16, 2024
- CVE-2022-2558131Monitor
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload.
HighCVSS 7.8Proof of conceptEPSS 1%classcms · classcmsMar 18, 2022
- CVE-2024-814421Monitor
ClassCMS Logo admin cross site scripting
MediumCVSS 5.3No exploitEPSS 0%classcms · classcmsAug 25, 2024
- CVE-2024-1250320Monitor
ClassCMS Model Management Page admin cross site scripting
MediumCVSS 5.1No exploitEPSS 1%classcms · classcmsDec 11, 2024
- CVE-2024-1266620Monitor
ClassCMS User Management Page admin insufficient privileges
MediumCVSS 5.1No exploitEPSS 1%classcms · classcmsDec 16, 2024
- CVE-2024-814520Monitor
ClassCMS Article admin cross site scripting
MediumCVSS 5.1No exploitEPSS 0%classcms · classcmsAug 25, 2024
- CVE-2024-5709719Monitor
ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
MediumCVSS 4.8No exploitEPSS 0%classcms · classcmsFeb 3, 2025