clippercms records
10 published records for vendor clippercms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-384 Session Fixation1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-41495No exploit | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.clippercms · clippercms · CWE-918 | Critical9.8 | — | 1.0% | Oct 13, 2022 |
39Monitor | CVE-2022-41497No exploit | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.clippercms · clippercms · CWE-918 | Critical9.8 | — | 1.0% | Oct 13, 2022 |
36Monitor | CVE-2018-19135Proof of concept | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).clippercms · clippercms · CWE-352 | High8.8 | — | 3.0% | Nov 11, 2018 |
35Monitor | CVE-2018-11571No exploit | ClipperCMS 1.3.3 allows Session Fixation.clippercms · clippercms · CWE-384 | High8.8 | — | 1.3% | May 30, 2018 |
29Monitor | CVE-2018-19424No exploit | ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.clippercms · clippercms · CWE-434 | High7.2 | — | 1.8% | Nov 21, 2018 |
21Monitor | CVE-2018-12101No exploit | CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.clippercms · clippercms · CWE-79 | Medium5.4 | — | 1.3% | Aug 15, 2019 |
21Monitor | CVE-2018-11572No exploit | ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.clippercms · clippercms · CWE-79 | Medium5.4 | — | 0.7% | May 30, 2018 |
20Monitor | CVE-2018-11332Proof of concept | Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 alclippercms · clippercms · CWE-79 | Medium4.8 | — | 1.9% | May 24, 2018 |
19Monitor | CVE-2018-13998No exploit | ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.clippercms · clippercms · CWE-79 | Medium4.8 | — | 0.7% | Jul 12, 2018 |
19Monitor | CVE-2018-13106No exploit | ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.clippercms · clippercms · CWE-79 | Medium4.8 | — | 0.7% | Jul 3, 2018 |
- CVE-2022-4149539Monitor
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
CriticalCVSS 9.8No exploitEPSS 1%clippercms · clippercmsOct 13, 2022
- CVE-2022-4149739Monitor
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
CriticalCVSS 9.8No exploitEPSS 1%clippercms · clippercmsOct 13, 2022
- CVE-2018-1913536Monitor
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).
HighCVSS 8.8Proof of conceptEPSS 3%clippercms · clippercmsNov 11, 2018
- CVE-2018-1157135Monitor
ClipperCMS 1.3.3 allows Session Fixation.
HighCVSS 8.8No exploitEPSS 1%clippercms · clippercmsMay 30, 2018
- CVE-2018-1942429Monitor
ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
HighCVSS 7.2No exploitEPSS 2%clippercms · clippercmsNov 21, 2018
- CVE-2018-1210121Monitor
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
MediumCVSS 5.4No exploitEPSS 1%clippercms · clippercmsAug 15, 2019
- CVE-2018-1157221Monitor
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
MediumCVSS 5.4No exploitEPSS 1%clippercms · clippercmsMay 30, 2018
- CVE-2018-1133220Monitor
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 al
MediumCVSS 4.8Proof of conceptEPSS 2%clippercms · clippercmsMay 24, 2018
- CVE-2018-1399819Monitor
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
MediumCVSS 4.8No exploitEPSS 1%clippercms · clippercmsJul 12, 2018
- CVE-2018-1310619Monitor
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
MediumCVSS 4.8No exploitEPSS 1%clippercms · clippercmsJul 3, 2018