cltphp records
7 published records for vendor cltphp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-30268No exploit | CLTPHP <=6.0 is vulnerable to Improper Input Validation.cltphp · cltphp · CWE-22 | Critical9.8 | — | 0.8% | May 4, 2023 |
39Monitor | CVE-2023-30264No exploit | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.cltphp · cltphp · CWE-434 | Critical9.8 | — | 0.7% | May 4, 2023 |
35Monitor | CVE-2023-30266No exploit | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.cltphp · cltphp · CWE-434 | High8.8 | — | 0.8% | Apr 26, 2023 |
32Monitor | CVE-2023-30269No exploit | CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.cltphp · cltphp · CWE-20 | High8.1 | — | 0.7% | Apr 26, 2023 |
26Monitor | CVE-2023-30265No exploit | CLTPHP <=6.0 is vulnerable to Directory Traversal.cltphp · cltphp · CWE-22 | Medium6.5 | — | 1.0% | Apr 26, 2023 |
24Monitor | CVE-2022-1085No exploit | CLTPHP POST Parameter cross site scriptingcltphp · cltphp · CWE-79 | Medium6.1 | — | 0.6% | Mar 29, 2022 |
24Monitor | CVE-2023-30267No exploit | CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php.cltphp · cltphp · CWE-79 | Medium6.1 | — | 0.4% | Apr 26, 2023 |
- CVE-2023-3026839Monitor
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
CriticalCVSS 9.8No exploitEPSS 1%cltphp · cltphpMay 4, 2023
- CVE-2023-3026439Monitor
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
CriticalCVSS 9.8No exploitEPSS 1%cltphp · cltphpMay 4, 2023
- CVE-2023-3026635Monitor
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
HighCVSS 8.8No exploitEPSS 1%cltphp · cltphpApr 26, 2023
- CVE-2023-3026932Monitor
CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
HighCVSS 8.1No exploitEPSS 1%cltphp · cltphpApr 26, 2023
- CVE-2023-3026526Monitor
CLTPHP <=6.0 is vulnerable to Directory Traversal.
MediumCVSS 6.5No exploitEPSS 1%cltphp · cltphpApr 26, 2023
- CVE-2022-108524Monitor
CLTPHP POST Parameter cross site scripting
MediumCVSS 6.1No exploitEPSS 1%cltphp · cltphpMar 29, 2022
- CVE-2023-3026724Monitor
CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php.
MediumCVSS 6.1No exploitEPSS 0%cltphp · cltphpApr 26, 2023