Exponentcms records
60 published records for vendor exponentcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 17
- With a fix record
- 1.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')28
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-20 Improper Input Validation7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
60 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2016-2242No exploit | Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.exponentcms · exponent cms · CWE-94 | Critical9.8 | — | 6.6% | Jan 23, 2017 |
40Plan | CVE-2016-7400Proof of concept | Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 4.7% | Feb 7, 2017 |
40Plan | CVE-2016-7791No exploit | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.exponentcms · exponent cms · CWE-20 | Critical9.8 | — | 3.9% | Jan 12, 2017 |
40Plan | CVE-2016-7790No exploit | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.exponentcms · exponent cms · CWE-20 | Critical9.8 | — | 3.9% | Jan 12, 2017 |
40Plan | CVE-2016-9019No exploit | SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 3.3% | Mar 7, 2017 |
40Plan | CVE-2016-9020No exploit | SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackeexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 3.1% | Mar 7, 2017 |
40Plan | CVE-2016-7788No exploit | SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7783No exploit | SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbiexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7782No exploit | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbiexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7781No exploit | SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackeexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7780No exploit | SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commandexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7784No exploit | SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows rexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 7, 2017 |
40Plan | CVE-2016-7789No exploit | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbiexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.5% | Mar 7, 2017 |
40Plan | CVE-2016-7095No exploit | Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unproteexponentcms · exponent cms · CWE-434 | Critical9.8 | — | 2.3% | Nov 3, 2016 |
40Plan | CVE-2016-7565No exploit | install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array paramexponentcms · exponent cms · CWE-284 | Critical9.8 | — | 2.3% | Feb 13, 2017 |
40Plan | CVE-2016-9087No exploit | SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier alloexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.2% | Mar 7, 2017 |
40Plan | CVE-2016-7443No exploit | Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong locatioexponentcms · exponent cms · CWE-434 | Critical9.8 | — | 2.2% | Mar 6, 2018 |
40Plan | CVE-2016-8899No exploit | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related exponentcms · exponent cms · CWE-74 | Critical9.8 | — | 2.1% | May 23, 2019 |
40Plan | CVE-2016-8900No exploit | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related exponentcms · exponent cms · CWE-74 | Critical9.8 | — | 2.1% | May 24, 2019 |
40Plan | CVE-2017-7991No exploit | Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modulesexponentcms · exponent cms · CWE-89 | Critical9.8 | — | 2.1% | Apr 21, 2017 |
40Plan | CVE-2017-5879No exploit | An issue was discovered in Exponent CMS 2.4.1.exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 1.9% | Feb 6, 2017 |
40Plan | CVE-2016-8897No exploit | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 1.8% | May 23, 2019 |
40Plan | CVE-2016-8898No exploit | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 1.8% | May 24, 2019 |
40Plan | CVE-2016-9481No exploit | In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments.exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 1.8% | Nov 29, 2016 |
39Monitor | CVE-2016-7453No exploit | The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.exponentcms · exponent cms · CWE-89 | Critical9.8 | — | 1.5% | Nov 3, 2016 |
- CVE-2016-224241Plan
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
CriticalCVSS 9.8No exploitEPSS 7%exponentcms · exponent cmsJan 23, 2017
- CVE-2016-740040Plan
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id
CriticalCVSS 9.8Proof of conceptEPSS 5%exponentcms · exponent cmsFeb 7, 2017
- CVE-2016-779140Plan
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.
CriticalCVSS 9.8No exploitEPSS 4%exponentcms · exponent cmsJan 12, 2017
- CVE-2016-779040Plan
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.
CriticalCVSS 9.8No exploitEPSS 4%exponentcms · exponent cmsJan 12, 2017
- CVE-2016-901940Plan
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-902040Plan
SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attacke
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778840Plan
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778340Plan
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778240Plan
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778140Plan
SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attacke
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778040Plan
SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL command
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778440Plan
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows r
CriticalCVSS 9.8No exploitEPSS 3%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-778940Plan
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbi
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-709540Plan
Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprote
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsNov 3, 2016
- CVE-2016-756540Plan
install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array param
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsFeb 13, 2017
- CVE-2016-908740Plan
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allo
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMar 7, 2017
- CVE-2016-744340Plan
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong locatio
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMar 6, 2018
- CVE-2016-889940Plan
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMay 23, 2019
- CVE-2016-890040Plan
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMay 24, 2019
- CVE-2017-799140Plan
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsApr 21, 2017
- CVE-2017-587940Plan
An issue was discovered in Exponent CMS 2.4.1.
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsFeb 6, 2017
- CVE-2016-889740Plan
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMay 23, 2019
- CVE-2016-889840Plan
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsMay 24, 2019
- CVE-2016-948140Plan
In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments.
CriticalCVSS 9.8No exploitEPSS 2%exponentcms · exponent cmsNov 29, 2016
- CVE-2016-745339Monitor
The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.
CriticalCVSS 9.8No exploitEPSS 1%exponentcms · exponent cmsNov 3, 2016