s-cms records
42 published records for vendor s-cms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')19
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-707 Improper Neutralization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-10708Proof of concept | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.s-cms · s-cms · CWE-89 | Critical9.8 | — | 2.6% | Apr 2, 2019 |
39Monitor | CVE-2021-37270No exploit | There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.s-cms · cms enterprise website construction system · CWE-862 | Critical9.8 | — | 1.5% | Sep 27, 2021 |
39Monitor | CVE-2018-18427No exploit | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.2% | Oct 17, 2018 |
39Monitor | CVE-2019-6805No exploit | SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Jan 25, 2019 |
39Monitor | CVE-2018-18887No exploit | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Oct 31, 2018 |
39Monitor | CVE-2018-20477No exploit | An issue was discovered in S-CMS 3.0.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Dec 25, 2018 |
39Monitor | CVE-2018-20479No exploit | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Dec 25, 2018 |
39Monitor | CVE-2018-20480No exploit | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Dec 25, 2018 |
39Monitor | CVE-2022-23336No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.s-cms · s-cms · CWE-89 | Critical9.8 | — | 1.1% | Feb 14, 2022 |
39Monitor | CVE-2023-51048No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 0.5% | Dec 21, 2023 |
39Monitor | CVE-2023-51049No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 0.5% | Dec 21, 2023 |
39Monitor | CVE-2023-51052No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 0.5% | Dec 21, 2023 |
39Monitor | CVE-2023-51051No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 0.5% | Dec 21, 2023 |
39Monitor | CVE-2023-51050No exploit | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.s-cms · s-cms · CWE-89 | Critical9.8 | — | 0.5% | Dec 21, 2023 |
36Monitor | CVE-2018-18426No exploit | s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.phs-cms · s-cms · CWE-94 | High8.8 | — | 2.4% | Oct 17, 2018 |
35Monitor | CVE-2019-10237No exploit | S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a relateds-cms · s-cms · CWE-352 | High8.8 | — | 0.6% | Mar 27, 2019 |
35Monitor | CVE-2019-9040No exploit | S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201s-cms · s-cms · CWE-352 | High8.8 | — | 0.6% | Feb 23, 2019 |
35Monitor | CVE-2023-7191No exploit | S-CMS reg.php sql injections-cms · s-cms · CWE-89 | High8.8 | — | 0.5% | Dec 31, 2023 |
35Monitor | CVE-2023-7189No exploit | A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | High8.8 | — | 0.5% | Dec 31, 2023 |
35Monitor | CVE-2023-7190No exploit | A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.s-cms · s-cms · CWE-89 | High8.8 | — | 0.5% | Dec 31, 2023 |
35Monitor | CVE-2018-19332No exploit | An issue was discovered in S-CMS v1.5.s-cms · s-cms · CWE-352 | High8.8 | — | 0.5% | Nov 17, 2018 |
30Monitor | CVE-2020-20340No exploit | A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infors-cms · s-cms · CWE-89 | High7.5 | — | 1.3% | Sep 1, 2021 |
30Monitor | CVE-2020-19954No exploit | An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.s-cms · s-cms · CWE-611 | High7.5 | — | 1.2% | Oct 14, 2021 |
30Monitor | CVE-2018-20018No exploit | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.s-cms · s-cms · CWE-89 | High7.5 | — | 1.2% | Dec 10, 2018 |
30Monitor | CVE-2018-20478No exploit | An issue was discovered in S-CMS 1.0.s-cms · s-cms · CWE-200 | High7.5 | — | 1.2% | Dec 25, 2018 |
- CVE-2019-1070840Plan
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%s-cms · s-cmsApr 2, 2019
- CVE-2021-3727039Monitor
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · cms enterprise website construction systemSep 27, 2021
- CVE-2018-1842739Monitor
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsOct 17, 2018
- CVE-2019-680539Monitor
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsJan 25, 2019
- CVE-2018-1888739Monitor
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsOct 31, 2018
- CVE-2018-2047739Monitor
An issue was discovered in S-CMS 3.0.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 25, 2018
- CVE-2018-2047939Monitor
An issue was discovered in S-CMS 1.0.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 25, 2018
- CVE-2018-2048039Monitor
An issue was discovered in S-CMS 1.0.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 25, 2018
- CVE-2022-2333639Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsFeb 14, 2022
- CVE-2023-5104839Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 21, 2023
- CVE-2023-5104939Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 21, 2023
- CVE-2023-5105239Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 21, 2023
- CVE-2023-5105139Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 21, 2023
- CVE-2023-5105039Monitor
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.
CriticalCVSS 9.8No exploitEPSS 1%s-cms · s-cmsDec 21, 2023
- CVE-2018-1842636Monitor
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.ph
HighCVSS 8.8No exploitEPSS 2%s-cms · s-cmsOct 17, 2018
- CVE-2019-1023735Monitor
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related
HighCVSS 8.8No exploitEPSS 1%s-cms · s-cmsMar 27, 2019
- CVE-2019-904035Monitor
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-201
HighCVSS 8.8No exploitEPSS 1%s-cms · s-cmsFeb 23, 2019
- CVE-2023-719135Monitor
S-CMS reg.php sql injection
HighCVSS 8.8No exploitEPSS 0%s-cms · s-cmsDec 31, 2023
- CVE-2023-718935Monitor
A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006.
HighCVSS 8.8No exploitEPSS 0%s-cms · s-cmsDec 31, 2023
- CVE-2023-719035Monitor
A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006.
HighCVSS 8.8No exploitEPSS 0%s-cms · s-cmsDec 31, 2023
- CVE-2018-1933235Monitor
An issue was discovered in S-CMS v1.5.
HighCVSS 8.8No exploitEPSS 0%s-cms · s-cmsNov 17, 2018
- CVE-2020-2034030Monitor
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database infor
HighCVSS 7.5No exploitEPSS 1%s-cms · s-cmsSep 1, 2021
- CVE-2020-1995430Monitor
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
HighCVSS 7.5No exploitEPSS 1%s-cms · s-cmsOct 14, 2021
- CVE-2018-2001830Monitor
S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
HighCVSS 7.5No exploitEPSS 1%s-cms · s-cmsDec 10, 2018
- CVE-2018-2047830Monitor
An issue was discovered in S-CMS 1.0.
HighCVSS 7.5No exploitEPSS 1%s-cms · s-cmsDec 25, 2018