Skip to content
Noroxi

cmswing records

8 published records for vendor cmswing.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule

    CriticalCVSS 9.8No exploitEPSS 2%

    cmswing · cmswingMar 23, 2022

  • An issue was found in CMSWing project version 1.3.8.

    CriticalCVSS 9.8No exploitEPSS 2%

    cmswing · cmswingFeb 1, 2021

  • An issue was found in CMSWing project version 1.3.8.

    CriticalCVSS 9.8No exploitEPSS 1%

    cmswing · cmswingFeb 1, 2021

  • An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious par

    CriticalCVSS 9.8No exploitEPSS 1%

    cmswing · cmswingFeb 1, 2021

  • CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.

    CriticalCVSS 9.8No exploitEPSS 1%

    cmswing · cmswingMar 23, 2022

  • CVE-2019-7649
    30Monitor

    global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.

    HighCVSS 7.5No exploitEPSS 1%

    cmswing · cmswingFeb 17, 2019

  • There is a cross site scripting vulnerability on CmsWing 1.3.7.

    MediumCVSS 5.4No exploitEPSS 1%

    cmswing · cmswingMay 17, 2021

  • There is a cross site scripting vulnerability on CmsWing 1.3.7.

    MediumCVSS 5.4No exploitEPSS 1%

    cmswing · cmswingMay 17, 2021