Skip to content
Noroxi

sunlight-cms records

3 published records for vendor sunlight-cms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

3 records
  • CVE-2007-2774
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the

    HighCVSS 7.5Proof of conceptEPSS 4%

    sunlight-cms · sunlight cmsMay 21, 2007

  • Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escala

    MediumCVSS 5.4No exploitEPSS 1%

    sunlight-cms · sunlight cmsJan 27, 2024

  • Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a craf

    MediumCVSS 5.4No exploitEPSS 0%

    sunlight-cms · sunlight cmsJan 27, 2024