Skip to content
Noroxi

elefantcms records

14 published records for vendor elefantcms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
92.9%
Median publish → KEV
No record has entered KEV

All records

14 records
  • An issue was discovered in Elefant CMS before 2.0.7.

    CriticalCVSS 9.8No exploitEPSS 4%

    elefantcms · elefantSep 12, 2018

  • An issue was discovered in Elefant CMS before 2.0.7.

    CriticalCVSS 9.8No exploitEPSS 4%

    elefantcms · elefantSep 12, 2018

  • apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" pr

    CriticalCVSS 9.8No exploitEPSS 2%

    elefantcms · elefantcmsAug 20, 2018

  • Elefant CMS layout code injection

    HighCVSS 8.8No exploitEPSS 1%

    elefantcms · elefant cmsJun 20, 2022

  • Elefant CMS File Upload drop privileges management

    HighCVSS 8.8No exploitEPSS 1%

    elefantcms · elefant cmsJun 20, 2022

  • An issue was discovered in Elefant CMS before 2.0.5.

    HighCVSS 8.8No exploitEPSS 1%

    elefantcms · elefantcmsSep 2, 2018

  • Elefant CMS cross-site request forgery

    HighCVSS 8.8No exploitEPSS 0%

    elefantcms · elefant cmsJun 20, 2022

  • Elefant CMS Version Comparison Persistent cross site scriting

    MediumCVSS 6.1No exploitEPSS 1%

    elefantcms · elefantcmsJun 20, 2022

  • Elefant CMS Persistent cross site scriting

    MediumCVSS 6.1No exploitEPSS 1%

    elefantcms · elefant cmsJun 20, 2022

  • Elefant CMS Title Persistent cross site scriting

    MediumCVSS 5.4No exploitEPSS 1%

    elefantcms · elefant cmsJun 20, 2022

  • Elefant CMS Blog Post Persistent cross site scriting

    MediumCVSS 5.4No exploitEPSS 1%

    elefantcms · elefant cmsJun 20, 2022

  • Elefant CMS extended Reflected cross site scriting

    MediumCVSS 5.4No exploitEPSS 0%

    elefantcms · elefant cmsJun 20, 2022

  • CVE-2012-1296
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x befo

    MediumCVSS 4.3No exploitEPSS 1%

    elefantcms · elefantcmsAug 26, 2012

  • CVE-2012-6521
    17Monitor

    Cross-site scripting (XSS) vulnerability in apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote attackers to inject arbitrar

    MediumCVSS 4.3No exploitEPSS 1%

    elefantcms · elefantcmsJan 23, 2013