Skip to content
Noroxi

foxcms records

15 published records for vendor foxcms.

All records

15 records
  • An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    foxcms · foxcmsMar 27, 2025

  • FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    foxcms · foxcmsFeb 26, 2025

  • An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary

    CriticalCVSS 9.8No exploitEPSS 1%

    foxcms · foxcmsFeb 26, 2025

  • FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

    CriticalCVSS 9.8No exploitEPSS 1%

    foxcms · foxcmsAug 7, 2025

  • A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.

    HighCVSS 8.8No exploitEPSS 0%

    foxcms · foxcmsAug 21, 2025

  • FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.

    HighCVSS 8.8No exploitEPSS 0%

    foxcms · foxcmsAug 25, 2025

  • In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

    HighCVSS 8.8No exploitEPSS 0%

    foxcms · foxcmsAug 27, 2025

  • Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

    HighCVSS 8.4No exploitEPSS 0%

    foxcms · foxcmsJun 3, 2025

  • FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

    HighCVSS 7.3No exploitEPSS 0%

    foxcms · foxcmsSep 8, 2025

  • FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

    HighCVSS 7.2No exploitEPSS 0%

    foxcms · foxcmsApr 17, 2025

  • In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.

    HighCVSS 7.2No exploitEPSS 0%

    foxcms · foxcmsApr 17, 2025

  • CVE-2025-5155
    21Monitor

    qianfox FoxCMS Article.php batchCope sql injection

    MediumCVSS 5.3No exploitEPSS 0%

    foxcms · foxcmsMay 25, 2025

  • SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.

    MediumCVSS 5.3No exploitEPSS 0%

    foxcms · foxcmsSep 3, 2025

  • FoxCMS Images.php batchCope sql injection

    LowCVSS 2.1No exploitEPSS 0%

    foxcms · foxcmsSep 11, 2025

  • qianfox FoxCMS Product.php edit cross site scripting

    LowCVSS 1.9No exploitEPSS 0%

    foxcms · foxcmsNov 9, 2025