Skip to content
Noroxi

poscms records

3 published records for vendor poscms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 24

Bar: total · dark part: CISA KEV.

Attack profile

All records

3 records
  • POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function

    HighCVSS 7.2No exploitEPSS 1%

    poscms · poscmsApr 19, 2018

  • POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function be

    HighCVSS 7.2No exploitEPSS 1%

    poscms · poscmsApr 19, 2018

  • Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index

    MediumCVSS 5.4No exploitEPSS 0%

    poscms · poscmsJan 30, 2024