poscms records
3 published records for vendor poscms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2018-10235No exploit | POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' functionposcms · poscms · CWE-94 | High7.2 | — | 1.5% | Apr 19, 2018 |
28Monitor | CVE-2018-10236No exploit | POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function beposcms · poscms · CWE-94 | High7.2 | — | 1.5% | Apr 19, 2018 |
21Monitor | CVE-2024-22569No exploit | Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /indexposcms · poscms · CWE-79 | Medium5.4 | — | 0.5% | Jan 30, 2024 |
- CVE-2018-1023528Monitor
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function
HighCVSS 7.2No exploitEPSS 1%poscms · poscmsApr 19, 2018
- CVE-2018-1023628Monitor
POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function be
HighCVSS 7.2No exploitEPSS 1%poscms · poscmsApr 19, 2018
- CVE-2024-2256921Monitor
Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index
MediumCVSS 5.4No exploitEPSS 0%poscms · poscmsJan 30, 2024