lovecms records
8 published records for vendor lovecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2008-5308Proof of concept | The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attaclovecms · the simple forum · CWE-264 | High7.5 | — | 7.3% | Dec 2, 2008 |
31Monitor | CVE-2008-3509Proof of concept | LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, whiclovecms · lovecms · CWE-94 | High7.5 | — | 3.4% | Aug 7, 2008 |
31Monitor | CVE-2007-1148Proof of concept | PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL lovecms · lovecms · CWE-94 | High7.5 | — | 2.7% | Mar 2, 2007 |
29Monitor | CVE-2008-7062Proof of concept | Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to lovecms · lovecms · CWE-264 | Medium6.8 | — | 6.7% | Aug 25, 2009 |
21Monitor | CVE-2007-1149Proof of concept | Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a ..lovecms · lovecms · CWE-22 | Medium5.0 | — | 3.7% | Mar 2, 2007 |
21Monitor | CVE-2008-5794Proof of concept | Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a lovecms · lovecms · CWE-22 | Medium5.0 | — | 2.6% | Dec 31, 2008 |
17Monitor | CVE-2007-1151Proof of concept | Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter lovecms · lovecms · CWE-79 | Medium4.3 | — | 1.6% | Mar 2, 2007 |
14Monitor | CVE-2007-1150No exploit | Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/contelovecms · lovecms · CWE-264 | Low3.6 | — | 1.0% | Mar 2, 2007 |
- CVE-2008-530832Monitor
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attac
HighCVSS 7.5Proof of conceptEPSS 7%lovecms · the simple forumDec 2, 2008
- CVE-2008-350931Monitor
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, whic
HighCVSS 7.5Proof of conceptEPSS 3%lovecms · lovecmsAug 7, 2008
- CVE-2007-114831Monitor
PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL
HighCVSS 7.5Proof of conceptEPSS 3%lovecms · lovecmsMar 2, 2007
- CVE-2008-706229Monitor
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to
MediumCVSS 6.8Proof of conceptEPSS 7%lovecms · lovecmsAug 25, 2009
- CVE-2007-114921Monitor
Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 4%lovecms · lovecmsMar 2, 2007
- CVE-2008-579421Monitor
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a
MediumCVSS 5.0Proof of conceptEPSS 3%lovecms · lovecmsDec 31, 2008
- CVE-2007-115117Monitor
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter
MediumCVSS 4.3Proof of conceptEPSS 2%lovecms · lovecmsMar 2, 2007
- CVE-2007-115014Monitor
Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/conte
LowCVSS 3.6No exploitEPSS 1%lovecms · lovecmsMar 2, 2007