Перейти к содержимому
Noroxi

Записи Impresscms

21 опубликованных записей вендора impresscms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
38,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

21 записей
  • CVE-2021-26599
    45В плане

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

    КритическаяCVSS 9,8Proof of conceptEPSS 21 %

    impresscms · impresscms27 мар. 2022 г.

  • CVE-2022-24977
    41В плане

    ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to u

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    impresscms · impresscms14 февр. 2022 г.

  • CVE-2021-26600
    41В плане

    ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    impresscms · impresscms27 мар. 2022 г.

  • CVE-2008-3453
    40В плане

    Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    impresscms · impresscms4 авг. 2008 г.

  • CVE-2022-50912
    37Наблюдать

    ImpressCMS 1.4.4 - Unrestricted File Upload

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    impresscms · impresscms13 янв. 2026 г.

  • CVE-2021-26601
    33Наблюдать

    ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %

    impresscms · impresscms27 мар. 2022 г.

  • CVE-2010-4271
    30Наблюдать

    SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    impresscms · impresscms16 нояб. 2010 г.

  • CVE-2022-26986
    29Наблюдать

    SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to

    ВысокаяCVSS 7,2Proof of conceptEPSS 4 %

    impresscms · impresscms5 апр. 2022 г.

  • CVE-2019-25703
    28Наблюдать

    ImpressCMS 1.3.11 SQL Injection via bid Parameter

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    impresscms · impresscms12 апр. 2026 г.

  • CVE-2008-5964
    27Наблюдать

    Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    impresscms · impresscms23 янв. 2009 г.

  • CVE-2014-1836
    26Наблюдать

    Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to

    СредняяCVSS 6,4Proof of conceptEPSS 4 %

    impresscms · impresscms1 июл. 2015 г.

  • CVE-2021-26598
    24Наблюдать

    ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by d

    СредняяCVSS 5,3Proof of conceptEPSS 11 %

    impresscms · impresscms27 мар. 2022 г.

  • CVE-2018-13983
    24Наблюдать

    ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    impresscms · impresscms6 мая 2019 г.

  • CVE-2012-0987
    24Наблюдать

    Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenti

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    impresscms · impresscms6 окт. 2012 г.

  • CVE-2021-28088
    21Наблюдать

    Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    impresscms · impresscms11 мар. 2021 г.

  • CVE-2020-17551
    19Наблюдать

    ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    impresscms · impresscms7 окт. 2020 г.

  • CVE-2023-37785
    19Наблюдать

    A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a c

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    impresscms · impresscms13 июл. 2023 г.

  • CVE-2012-0986
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attacke

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    impresscms · impresscms6 окт. 2012 г.

  • CVE-2010-4616
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    impresscms · impresscms29 дек. 2010 г.

  • CVE-2008-6360
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attack

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    impresscms · impresscms2 мар. 2009 г.

  • CVE-2014-4036
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web s

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    impresscms · impresscms11 июн. 2014 г.