ecisp records
7 published records for vendor ecisp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2022-44088No exploit | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.ecisp · espcms · CWE-94 | Critical9.8 | — | 20.1% | Nov 10, 2022 |
39Monitor | CVE-2022-44087No exploit | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.ecisp · espcms · CWE-94 | Critical9.8 | — | 1.6% | Nov 10, 2022 |
39Monitor | CVE-2022-44089No exploit | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.ecisp · espcms · CWE-94 | Critical9.8 | — | 1.6% | Nov 10, 2022 |
30Monitor | CVE-2020-18913No exploit | EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parametecisp · espcms-p8 · CWE-89 | High7.5 | — | 1.3% | Aug 24, 2021 |
29Monitor | CVE-2022-33085No exploit | ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_puecisp · espcms-p8 | High7.2 | — | 1.9% | Jun 30, 2022 |
28Monitor | CVE-2023-23007No exploit | An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function nodecisp · espcms · CWE-89 | High7.2 | — | 0.6% | Feb 17, 2023 |
19Monitor | CVE-2020-18404No exploit | An issue was discovered in espcms version P8.18101601.ecisp · espcms · CWE-79 | Medium4.8 | — | 0.4% | Jun 27, 2023 |
- CVE-2022-4408845Plan
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
CriticalCVSS 9.8No exploitEPSS 20%ecisp · espcmsNov 10, 2022
- CVE-2022-4408739Monitor
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
CriticalCVSS 9.8No exploitEPSS 2%ecisp · espcmsNov 10, 2022
- CVE-2022-4408939Monitor
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
CriticalCVSS 9.8No exploitEPSS 2%ecisp · espcmsNov 10, 2022
- CVE-2020-1891330Monitor
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array paramet
HighCVSS 7.5No exploitEPSS 1%ecisp · espcms-p8Aug 24, 2021
- CVE-2022-3308529Monitor
ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_pu
HighCVSS 7.2No exploitEPSS 2%ecisp · espcms-p8Jun 30, 2022
- CVE-2023-2300728Monitor
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function nod
HighCVSS 7.2No exploitEPSS 1%ecisp · espcmsFeb 17, 2023
- CVE-2020-1840419Monitor
An issue was discovered in espcms version P8.18101601.
MediumCVSS 4.8No exploitEPSS 0%ecisp · espcmsJun 27, 2023