easycms records
12 published records for vendor easycms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-23358No exploit | EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php.easycms · easycms · CWE-89 | Critical9.8 | — | 1.2% | Feb 16, 2022 |
35Monitor | CVE-2020-24271No exploit | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuseasycms · easycms · CWE-352 | High8.8 | — | 0.6% | Feb 1, 2021 |
35Monitor | CVE-2019-6294No exploit | An issue was discovered in EasyCMS 1.5.easycms · easycms · CWE-352 | High8.8 | — | 0.5% | Jan 15, 2019 |
35Monitor | CVE-2018-16345No exploit | An issue was discovered in EasyCMS 1.5.easycms · easycms · CWE-352 | High8.8 | — | 0.5% | Sep 2, 2018 |
26Monitor | CVE-2018-12971No exploit | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.easycms · easycms · CWE-352 | Medium6.5 | — | 0.4% | Jun 29, 2018 |
24Monitor | CVE-2018-16759No exploit | The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS viaeasycms · easycms · CWE-79 | Medium6.1 | — | 0.7% | Sep 9, 2018 |
24Monitor | CVE-2018-10374No exploit | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.easycms · easycms · CWE-79 | Medium6.1 | — | 0.7% | Apr 25, 2018 |
24Monitor | CVE-2018-17113No exploit | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, easycms · easycms · CWE-79 | Medium6.1 | — | 0.6% | Sep 17, 2018 |
22Monitor | CVE-2026-1105No exploit | EasyCMS UserAction.class.php sql injectioneasycms · easycms · CWE-74 | Medium5.5 | — | 0.5% | Jan 17, 2026 |
19Monitor | CVE-2018-16773No exploit | EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.easycms · easycms · CWE-79 | Medium4.8 | — | 0.5% | Sep 10, 2018 |
8Monitor | CVE-2026-3785No exploit | EasyCMS Request Parameter RbacnodeAction.class.php sql injectioneasycms · easycms · CWE-74 | Low2.1 | — | 0.5% | Mar 8, 2026 |
8Monitor | CVE-2026-3786Proof of concept | EasyCMS Request Parameter RbacuserAction.class.php sql injectioneasycms · easycms · CWE-74 | Low2.1 | — | 0.5% | Mar 8, 2026 |
- CVE-2022-2335839Monitor
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php.
CriticalCVSS 9.8No exploitEPSS 1%easycms · easycmsFeb 16, 2022
- CVE-2020-2427135Monitor
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacus
HighCVSS 8.8No exploitEPSS 1%easycms · easycmsFeb 1, 2021
- CVE-2019-629435Monitor
An issue was discovered in EasyCMS 1.5.
HighCVSS 8.8No exploitEPSS 1%easycms · easycmsJan 15, 2019
- CVE-2018-1634535Monitor
An issue was discovered in EasyCMS 1.5.
HighCVSS 8.8No exploitEPSS 1%easycms · easycmsSep 2, 2018
- CVE-2018-1297126Monitor
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
MediumCVSS 6.5No exploitEPSS 0%easycms · easycmsJun 29, 2018
- CVE-2018-1675924Monitor
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via
MediumCVSS 6.1No exploitEPSS 1%easycms · easycmsSep 9, 2018
- CVE-2018-1037424Monitor
EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.
MediumCVSS 6.1No exploitEPSS 1%easycms · easycmsApr 25, 2018
- CVE-2018-1711324Monitor
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter,
MediumCVSS 6.1No exploitEPSS 1%easycms · easycmsSep 17, 2018
- CVE-2026-110522Monitor
EasyCMS UserAction.class.php sql injection
MediumCVSS 5.5No exploitEPSS 0%easycms · easycmsJan 17, 2026
- CVE-2018-1677319Monitor
EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field.
MediumCVSS 4.8No exploitEPSS 1%easycms · easycmsSep 10, 2018
- CVE-2026-37858Monitor
EasyCMS Request Parameter RbacnodeAction.class.php sql injection
LowCVSS 2.1No exploitEPSS 0%easycms · easycmsMar 8, 2026
- CVE-2026-37868Monitor
EasyCMS Request Parameter RbacuserAction.class.php sql injection
LowCVSS 2.1Proof of conceptEPSS 0%easycms · easycmsMar 8, 2026