pescms records
7 published records for vendor pescms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-16370Proof of concept | In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php filepescms · pescms team · CWE-434 | Critical9.8 | — | 1.8% | Sep 2, 2018 |
26Monitor | CVE-2021-31677No exploit | An issue was discovered in PESCMS-V2.3.3.pescms · pescms team · CWE-352 | Medium6.5 | — | 0.6% | Jul 6, 2022 |
26Monitor | CVE-2021-31679No exploit | An issue was discovered in PESCMS-V2.3.3.pescms · pescms team · CWE-352 | Medium6.5 | — | 0.6% | Jul 6, 2022 |
26Monitor | CVE-2021-31678No exploit | An issue was discovered in PESCMS-V2.3.3.pescms · pescms team · CWE-352 | Medium6.5 | — | 0.6% | Jul 6, 2022 |
25Monitor | CVE-2020-28092Proof of concept | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&pescms · pescms team · CWE-79 | Medium6.1 | — | 2.7% | Nov 17, 2020 |
24Monitor | CVE-2021-31676No exploit | A reflected XSS was discovered in PESCMS-V2.3.3.pescms · pescms team · CWE-79 | Medium6.1 | — | 0.9% | Jul 6, 2022 |
24Monitor | CVE-2018-16371No exploit | PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=pescms · pescms team · CWE-79 | Medium6.1 | — | 0.7% | Sep 2, 2018 |
- CVE-2018-1637040Plan
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file
CriticalCVSS 9.8Proof of conceptEPSS 2%pescms · pescms teamSep 2, 2018
- CVE-2021-3167726Monitor
An issue was discovered in PESCMS-V2.3.3.
MediumCVSS 6.5No exploitEPSS 1%pescms · pescms teamJul 6, 2022
- CVE-2021-3167926Monitor
An issue was discovered in PESCMS-V2.3.3.
MediumCVSS 6.5No exploitEPSS 1%pescms · pescms teamJul 6, 2022
- CVE-2021-3167826Monitor
An issue was discovered in PESCMS-V2.3.3.
MediumCVSS 6.5No exploitEPSS 1%pescms · pescms teamJul 6, 2022
- CVE-2020-2809225Monitor
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&
MediumCVSS 6.1Proof of conceptEPSS 3%pescms · pescms teamNov 17, 2020
- CVE-2021-3167624Monitor
A reflected XSS was discovered in PESCMS-V2.3.3.
MediumCVSS 6.1No exploitEPSS 1%pescms · pescms teamJul 6, 2022
- CVE-2018-1637124Monitor
PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=
MediumCVSS 6.1No exploitEPSS 1%pescms · pescms teamSep 2, 2018