flatcore records
23 published records for vendor flatcore.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2021-41403No exploit | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.flatcore · flatcore-cms · CWE-918 | Critical9.8 | — | 19.1% | Jun 15, 2022 |
42Plan | CVE-2021-39608Proof of concept | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user eflatcore · flatcore-cms · CWE-434 | High7.2 | — | 45.9% | Aug 23, 2021 |
39Monitor | CVE-2017-7878No exploit | SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.flatcore · flatcore-cms · CWE-89 | Critical9.8 | — | 1.0% | Apr 14, 2017 |
36Monitor | CVE-2019-13961Proof of concept | A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.flatcore · flatcore · CWE-352 | High8.8 | — | 2.3% | Jul 18, 2019 |
35Monitor | CVE-2021-41402No exploit | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.flatcore · flatcore-cms · CWE-94 | High8.8 | — | 1.4% | Jun 16, 2022 |
35Monitor | CVE-2017-7877No exploit | CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.flatcore · flatcore-cms · CWE-352 | High8.8 | — | 0.9% | Apr 14, 2017 |
31Monitor | CVE-2017-8868No exploit | acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php.flatcore · flatcore-cms · CWE-22 | High7.5 | — | 1.9% | May 10, 2017 |
30Monitor | CVE-2019-10652Proof of concept | An issue was discovered in flatCore 1.4.7.flatcore · flatcore · CWE-434 | High7.2 | — | 7.0% | Mar 30, 2019 |
30Monitor | CVE-2017-7879No exploit | SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.flatcore · flatcore-cms · CWE-89 | High7.5 | — | 1.0% | Apr 14, 2017 |
29Monitor | CVE-2020-17452No exploit | flatCore before 1.5.7 allows upload and execution of a .php file by an admin.flatcore · flatcore · CWE-434 | High7.2 | — | 2.4% | Aug 9, 2020 |
26Monitor | CVE-2021-23837No exploit | An issue was discovered in flatCore before 2.0.0 build 139.flatcore · flatcore · CWE-89 | Medium6.5 | — | 1.5% | Jan 15, 2021 |
26Monitor | CVE-2021-3745No exploit | Unrestricted Upload of File with Dangerous Type in flatcore/flatcore-cmsflatcore · flatcore-cms · CWE-434 | Medium6.6 | — | 1.1% | Oct 28, 2021 |
24Monitor | CVE-2017-1000428No exploit | flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored flatcore · flatcore-cms · CWE-79 | Medium6.1 | — | 0.8% | Jan 9, 2018 |
24Monitor | CVE-2017-9451No exploit | Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript viaflatcore · flatcore · CWE-79 | Medium6.1 | — | 0.7% | Jun 6, 2017 |
24Monitor | CVE-2021-42245No exploit | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.flatcore · flatcore-cms · CWE-79 | Medium6.1 | — | 0.7% | Jun 6, 2022 |
24Monitor | CVE-2022-43118No exploit | A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted paflatcore · flatcore-cms · CWE-79 | Medium6.1 | — | 0.4% | Nov 9, 2022 |
22Monitor | CVE-2021-39609No exploit | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.flatcore · flatcore-cms · CWE-79 | Medium5.4 | — | 1.7% | Aug 23, 2021 |
21Monitor | CVE-2021-40902No exploit | flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.flatcore · flatcore-cms · CWE-79 | Medium5.4 | — | 0.5% | Jun 13, 2022 |
21Monitor | CVE-2021-40555No exploit | Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new flatcore · flatcore · CWE-79 | Medium5.4 | — | 0.4% | Feb 16, 2023 |
20Monitor | CVE-2021-23835No exploit | An issue was discovered in flatCore before 2.0.0 build 139.flatcore · flatcore · CWE-20 | Medium4.9 | — | 1.7% | Jan 15, 2021 |
19Monitor | CVE-2021-23838No exploit | An issue was discovered in flatCore before 2.0.0 build 139.flatcore · flatcore · CWE-79 | Medium4.8 | — | 1.0% | Jan 15, 2021 |
19Monitor | CVE-2021-23836No exploit | An issue was discovered in flatCore before 2.0.0 build 139.flatcore · flatcore · CWE-79 | Medium4.8 | — | 0.9% | Jan 15, 2021 |
19Monitor | CVE-2020-17451No exploit | flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or paflatcore · flatcore · CWE-79 | Medium4.8 | — | 0.6% | Aug 9, 2020 |
- CVE-2021-4140345Plan
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
CriticalCVSS 9.8No exploitEPSS 19%flatcore · flatcore-cmsJun 15, 2022
- CVE-2021-3960842Plan
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user e
HighCVSS 7.2Proof of conceptEPSS 46%flatcore · flatcore-cmsAug 23, 2021
- CVE-2017-787839Monitor
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
CriticalCVSS 9.8No exploitEPSS 1%flatcore · flatcore-cmsApr 14, 2017
- CVE-2019-1396136Monitor
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
HighCVSS 8.8Proof of conceptEPSS 2%flatcore · flatcoreJul 18, 2019
- CVE-2021-4140235Monitor
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
HighCVSS 8.8No exploitEPSS 1%flatcore · flatcore-cmsJun 16, 2022
- CVE-2017-787735Monitor
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
HighCVSS 8.8No exploitEPSS 1%flatcore · flatcore-cmsApr 14, 2017
- CVE-2017-886831Monitor
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php.
HighCVSS 7.5No exploitEPSS 2%flatcore · flatcore-cmsMay 10, 2017
- CVE-2019-1065230Monitor
An issue was discovered in flatCore 1.4.7.
HighCVSS 7.2Proof of conceptEPSS 7%flatcore · flatcoreMar 30, 2019
- CVE-2017-787930Monitor
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
HighCVSS 7.5No exploitEPSS 1%flatcore · flatcore-cmsApr 14, 2017
- CVE-2020-1745229Monitor
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
HighCVSS 7.2No exploitEPSS 2%flatcore · flatcoreAug 9, 2020
- CVE-2021-2383726Monitor
An issue was discovered in flatCore before 2.0.0 build 139.
MediumCVSS 6.5No exploitEPSS 1%flatcore · flatcoreJan 15, 2021
- CVE-2021-374526Monitor
Unrestricted Upload of File with Dangerous Type in flatcore/flatcore-cms
MediumCVSS 6.6No exploitEPSS 1%flatcore · flatcore-cmsOct 28, 2021
- CVE-2017-100042824Monitor
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored
MediumCVSS 6.1No exploitEPSS 1%flatcore · flatcore-cmsJan 9, 2018
- CVE-2017-945124Monitor
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via
MediumCVSS 6.1No exploitEPSS 1%flatcore · flatcoreJun 6, 2017
- CVE-2021-4224524Monitor
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
MediumCVSS 6.1No exploitEPSS 1%flatcore · flatcore-cmsJun 6, 2022
- CVE-2022-4311824Monitor
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
MediumCVSS 6.1No exploitEPSS 0%flatcore · flatcore-cmsNov 9, 2022
- CVE-2021-3960922Monitor
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
MediumCVSS 5.4No exploitEPSS 2%flatcore · flatcore-cmsAug 23, 2021
- CVE-2021-4090221Monitor
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
MediumCVSS 5.4No exploitEPSS 0%flatcore · flatcore-cmsJun 13, 2022
- CVE-2021-4055521Monitor
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new
MediumCVSS 5.4No exploitEPSS 0%flatcore · flatcoreFeb 16, 2023
- CVE-2021-2383520Monitor
An issue was discovered in flatCore before 2.0.0 build 139.
MediumCVSS 4.9No exploitEPSS 2%flatcore · flatcoreJan 15, 2021
- CVE-2021-2383819Monitor
An issue was discovered in flatCore before 2.0.0 build 139.
MediumCVSS 4.8No exploitEPSS 1%flatcore · flatcoreJan 15, 2021
- CVE-2021-2383619Monitor
An issue was discovered in flatCore before 2.0.0 build 139.
MediumCVSS 4.8No exploitEPSS 1%flatcore · flatcoreJan 15, 2021
- CVE-2020-1745119Monitor
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or pa
MediumCVSS 4.8No exploitEPSS 1%flatcore · flatcoreAug 9, 2020