Записи Impresscms
21 опубликованных записей вендора impresscms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 38,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2021-26599Proof of concept | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.impresscms · impresscms · CWE-89 | Критическая9,8 | — | 21,0 % | 27 мар. 2022 г. |
41В плане | CVE-2022-24977Эксплойта нет | ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to uimpresscms · impresscms · CWE-22 | Критическая9,8 | — | 6,4 % | 14 февр. 2022 г. |
41В плане | CVE-2021-26600Эксплойта нет | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).impresscms · impresscms · CWE-843 | Критическая9,8 | — | 5,6 % | 27 мар. 2022 г. |
40В плане | CVE-2008-3453Эксплойта нет | Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few filesimpresscms · impresscms | Критическая10,0 | — | 1,4 % | 4 авг. 2008 г. |
37Наблюдать | CVE-2022-50912Эксплойта нет | ImpressCMS 1.4.4 - Unrestricted File Uploadimpresscms · impresscms · CWE-434 | Критическая9,3 | — | 1,1 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2021-26601Эксплойта нет | ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.impresscms · impresscms · CWE-22 | Высокая8,1 | — | 3,2 % | 27 мар. 2022 г. |
30Наблюдать | CVE-2010-4271Эксплойта нет | SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectorsimpresscms · impresscms · CWE-89 | Высокая7,5 | — | 1,1 % | 16 нояб. 2010 г. |
29Наблюдать | CVE-2022-26986Proof of concept | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to impresscms · impresscms · CWE-89 | Высокая7,2 | — | 4,1 % | 5 апр. 2022 г. |
28Наблюдать | CVE-2019-25703Эксплойта нет | ImpressCMS 1.3.11 SQL Injection via bid Parameterimpresscms · impresscms · CWE-89 | Высокая7,1 | — | 0,3 % | 12 апр. 2026 г. |
27Наблюдать | CVE-2008-5964Эксплойта нет | Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSIDimpresscms · impresscms · CWE-287 | Средняя6,8 | — | 1,5 % | 23 янв. 2009 г. |
26Наблюдать | CVE-2014-1836Proof of concept | Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to impresscms · impresscms · CWE-22 | Средняя6,4 | — | 3,7 % | 1 июл. 2015 г. |
24Наблюдать | CVE-2021-26598Proof of concept | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by dimpresscms · impresscms · CWE-287 | Средняя5,3 | — | 10,5 % | 27 мар. 2022 г. |
24Наблюдать | CVE-2018-13983Эксплойта нет | ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheckimpresscms · impresscms · CWE-79 | Средняя6,1 | — | 1,5 % | 6 мая 2019 г. |
24Наблюдать | CVE-2012-0987Эксплойта нет | Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authentiimpresscms · impresscms · CWE-22 | Средняя6,0 | — | 1,5 % | 6 окт. 2012 г. |
21Наблюдать | CVE-2021-28088Эксплойта нет | Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web impresscms · impresscms · CWE-79 | Средняя5,4 | — | 0,9 % | 11 мар. 2021 г. |
19Наблюдать | CVE-2020-17551Эксплойта нет | ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.impresscms · impresscms · CWE-79 | Средняя4,8 | — | 1,1 % | 7 окт. 2020 г. |
19Наблюдать | CVE-2023-37785Эксплойта нет | A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a cimpresscms · impresscms · CWE-79 | Средняя4,8 | — | 0,5 % | 13 июл. 2023 г. |
18Наблюдать | CVE-2012-0986Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackeimpresscms · impresscms · CWE-79 | Средняя4,3 | — | 1,7 % | 6 окт. 2012 г. |
17Наблюдать | CVE-2010-4616Эксплойта нет | Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before impresscms · impresscms · CWE-79 | Средняя4,3 | — | 1,1 % | 29 дек. 2010 г. |
17Наблюдать | CVE-2008-6360Эксплойта нет | Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attackimpresscms · impresscms · CWE-79 | Средняя4,3 | — | 1,0 % | 2 мар. 2009 г. |
17Наблюдать | CVE-2014-4036Эксплойта нет | Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web simpresscms · impresscms · CWE-79 | Средняя4,3 | — | 1,0 % | 11 июн. 2014 г. |
- CVE-2021-2659945В плане
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
КритическаяCVSS 9,8Proof of conceptEPSS 21 %impresscms · impresscms27 мар. 2022 г.
- CVE-2022-2497741В плане
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to u
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %impresscms · impresscms14 февр. 2022 г.
- CVE-2021-2660041В плане
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %impresscms · impresscms27 мар. 2022 г.
- CVE-2008-345340В плане
Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %impresscms · impresscms4 авг. 2008 г.
- CVE-2022-5091237Наблюдать
ImpressCMS 1.4.4 - Unrestricted File Upload
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %impresscms · impresscms13 янв. 2026 г.
- CVE-2021-2660133Наблюдать
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %impresscms · impresscms27 мар. 2022 г.
- CVE-2010-427130Наблюдать
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %impresscms · impresscms16 нояб. 2010 г.
- CVE-2022-2698629Наблюдать
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to
ВысокаяCVSS 7,2Proof of conceptEPSS 4 %impresscms · impresscms5 апр. 2022 г.
- CVE-2019-2570328Наблюдать
ImpressCMS 1.3.11 SQL Injection via bid Parameter
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %impresscms · impresscms12 апр. 2026 г.
- CVE-2008-596427Наблюдать
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID
СредняяCVSS 6,8Эксплойта нетEPSS 2 %impresscms · impresscms23 янв. 2009 г.
- CVE-2014-183626Наблюдать
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to
СредняяCVSS 6,4Proof of conceptEPSS 4 %impresscms · impresscms1 июл. 2015 г.
- CVE-2021-2659824Наблюдать
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by d
СредняяCVSS 5,3Proof of conceptEPSS 11 %impresscms · impresscms27 мар. 2022 г.
- CVE-2018-1398324Наблюдать
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck
СредняяCVSS 6,1Эксплойта нетEPSS 2 %impresscms · impresscms6 мая 2019 г.
- CVE-2012-098724Наблюдать
Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenti
СредняяCVSS 6,0Эксплойта нетEPSS 2 %impresscms · impresscms6 окт. 2012 г.
- CVE-2021-2808821Наблюдать
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web
СредняяCVSS 5,4Эксплойта нетEPSS 1 %impresscms · impresscms11 мар. 2021 г.
- CVE-2020-1755119Наблюдать
ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %impresscms · impresscms7 окт. 2020 г.
- CVE-2023-3778519Наблюдать
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a c
СредняяCVSS 4,8Эксплойта нетEPSS 0 %impresscms · impresscms13 июл. 2023 г.
- CVE-2012-098618Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attacke
СредняяCVSS 4,3Эксплойта нетEPSS 2 %impresscms · impresscms6 окт. 2012 г.
- CVE-2010-461617Наблюдать
Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before
СредняяCVSS 4,3Эксплойта нетEPSS 1 %impresscms · impresscms29 дек. 2010 г.
- CVE-2008-636017Наблюдать
Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attack
СредняяCVSS 4,3Эксплойта нетEPSS 1 %impresscms · impresscms2 мар. 2009 г.
- CVE-2014-403617Наблюдать
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web s
СредняяCVSS 4,3Эксплойта нетEPSS 1 %impresscms · impresscms11 июн. 2014 г.