native-php-cms project records
6 published records for vendor native-php-cms project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-1392 Use of Default Credentials1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-36503No exploit | SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php fnative-php-cms project · native-php-cms · CWE-89 | Critical9.8 | — | 0.9% | Feb 3, 2023 |
27Monitor | CVE-2025-0482No exploit | Fanli2012 native-php-cms user_recoverpwd.php default credentialsnative-php-cms project · native-php-cms · CWE-1392 | Medium6.9 | — | 0.6% | Jan 15, 2025 |
21Monitor | CVE-2025-0490No exploit | Fanli2012 native-php-cms article_dodel.php sql injectionnative-php-cms project · native-php-cms · CWE-74 | Medium5.3 | — | 0.6% | Jan 15, 2025 |
21Monitor | CVE-2025-0488No exploit | Fanli2012 native-php-cms product_list.php sql injectionnative-php-cms project · native-php-cms · CWE-74 | Medium5.3 | — | 0.5% | Jan 15, 2025 |
21Monitor | CVE-2025-0489No exploit | Fanli2012 native-php-cms friendlink_dodel.php sql injectionnative-php-cms project · native-php-cms · CWE-74 | Medium5.3 | — | 0.5% | Jan 15, 2025 |
21Monitor | CVE-2025-0483No exploit | Fanli2012 native-php-cms jump.php cross site scriptingnative-php-cms project · native-php-cms · CWE-79 | Medium5.3 | — | 0.3% | Jan 15, 2025 |
- CVE-2021-3650339Monitor
SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php f
CriticalCVSS 9.8No exploitEPSS 1%native-php-cms project · native-php-cmsFeb 3, 2023
- CVE-2025-048227Monitor
Fanli2012 native-php-cms user_recoverpwd.php default credentials
MediumCVSS 6.9No exploitEPSS 1%native-php-cms project · native-php-cmsJan 15, 2025
- CVE-2025-049021Monitor
Fanli2012 native-php-cms article_dodel.php sql injection
MediumCVSS 5.3No exploitEPSS 1%native-php-cms project · native-php-cmsJan 15, 2025
- CVE-2025-048821Monitor
Fanli2012 native-php-cms product_list.php sql injection
MediumCVSS 5.3No exploitEPSS 0%native-php-cms project · native-php-cmsJan 15, 2025
- CVE-2025-048921Monitor
Fanli2012 native-php-cms friendlink_dodel.php sql injection
MediumCVSS 5.3No exploitEPSS 0%native-php-cms project · native-php-cmsJan 15, 2025
- CVE-2025-048321Monitor
Fanli2012 native-php-cms jump.php cross site scripting
MediumCVSS 5.3No exploitEPSS 0%native-php-cms project · native-php-cmsJan 15, 2025