Записи foxcms
15 опубликованных записей вендора foxcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2025-29306Proof of concept | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.foxcms · foxcms · CWE-94 | Критическая9,8 | — | 46,6 % | 27 мар. 2025 г. |
39Наблюдать | CVE-2025-25789Эксплойта нет | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.foxcms · foxcms · CWE-94 | Критическая9,8 | — | 1,3 % | 26 февр. 2025 г. |
39Наблюдать | CVE-2025-25790Эксплойта нет | An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitraryfoxcms · foxcms · CWE-434 | Критическая9,8 | — | 0,9 % | 26 февр. 2025 г. |
39Наблюдать | CVE-2025-50692Эксплойта нет | FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.foxcms · foxcms · CWE-94 | Критическая9,8 | — | 0,7 % | 7 авг. 2025 г. |
35Наблюдать | CVE-2025-55420Эксплойта нет | A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.foxcms · foxcms · CWE-79 | Высокая8,8 | — | 0,5 % | 21 авг. 2025 г. |
35Наблюдать | CVE-2025-55409Эксплойта нет | FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.foxcms · foxcms · CWE-79 | Высокая8,8 | — | 0,5 % | 25 авг. 2025 г. |
35Наблюдать | CVE-2025-55422Эксплойта нет | In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.foxcms · foxcms · CWE-79 | Высокая8,8 | — | 0,4 % | 27 авг. 2025 г. |
33Наблюдать | CVE-2025-46154Эксплойта нет | Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.foxcms · foxcms · CWE-89 | Высокая8,4 | — | 0,2 % | 3 июн. 2025 г. |
29Наблюдать | CVE-2025-56630Эксплойта нет | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.foxcms · foxcms · CWE-89 | Высокая7,3 | — | 0,2 % | 8 сент. 2025 г. |
28Наблюдать | CVE-2025-29181Эксплойта нет | FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.foxcms · foxcms · CWE-89 | Высокая7,2 | — | 0,4 % | 17 апр. 2025 г. |
28Наблюдать | CVE-2025-29180Эксплойта нет | In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.foxcms · foxcms · CWE-89 | Высокая7,2 | — | 0,4 % | 17 апр. 2025 г. |
21Наблюдать | CVE-2025-5155Эксплойта нет | qianfox FoxCMS Article.php batchCope sql injectionfoxcms · foxcms · CWE-74 | Средняя5,3 | — | 0,5 % | 25 мая 2025 г. |
21Наблюдать | CVE-2025-56435Эксплойта нет | SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.foxcms · foxcms · CWE-89 | Средняя5,3 | — | 0,4 % | 3 сент. 2025 г. |
8Наблюдать | CVE-2025-10251Эксплойта нет | FoxCMS Images.php batchCope sql injectionfoxcms · foxcms · CWE-74 | Низкая2,1 | — | 0,4 % | 11 сент. 2025 г. |
7Наблюдать | CVE-2025-12920Эксплойта нет | qianfox FoxCMS Product.php edit cross site scriptingfoxcms · foxcms · CWE-79 | Низкая1,9 | — | 0,3 % | 9 нояб. 2025 г. |
- CVE-2025-2930653В плане
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
КритическаяCVSS 9,8Proof of conceptEPSS 47 %foxcms · foxcms27 мар. 2025 г.
- CVE-2025-2578939Наблюдать
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %foxcms · foxcms26 февр. 2025 г.
- CVE-2025-2579039Наблюдать
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %foxcms · foxcms26 февр. 2025 г.
- CVE-2025-5069239Наблюдать
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %foxcms · foxcms7 авг. 2025 г.
- CVE-2025-5542035Наблюдать
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %foxcms · foxcms21 авг. 2025 г.
- CVE-2025-5540935Наблюдать
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %foxcms · foxcms25 авг. 2025 г.
- CVE-2025-5542235Наблюдать
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %foxcms · foxcms27 авг. 2025 г.
- CVE-2025-4615433Наблюдать
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %foxcms · foxcms3 июн. 2025 г.
- CVE-2025-5663029Наблюдать
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %foxcms · foxcms8 сент. 2025 г.
- CVE-2025-2918128Наблюдать
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %foxcms · foxcms17 апр. 2025 г.
- CVE-2025-2918028Наблюдать
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %foxcms · foxcms17 апр. 2025 г.
- CVE-2025-515521Наблюдать
qianfox FoxCMS Article.php batchCope sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 0 %foxcms · foxcms25 мая 2025 г.
- CVE-2025-5643521Наблюдать
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %foxcms · foxcms3 сент. 2025 г.
- CVE-2025-102518Наблюдать
FoxCMS Images.php batchCope sql injection
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %foxcms · foxcms11 сент. 2025 г.
- CVE-2025-129207Наблюдать
qianfox FoxCMS Product.php edit cross site scripting
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %foxcms · foxcms9 нояб. 2025 г.