blackcat-cms kayıtları
blackcat-cms üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2020-25453Kavram kanıtı | An issue was discovered in BlackCat CMS before 1.4.blackcat-cms · blackcat cms · CWE-352 | Yüksek8,8 | — | %6,3 | 15 Eyl 2020 |
35İzleyin | CVE-2015-5079Kavram kanıtı | Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a ..blackcat-cms · blackcat cms · CWE-22 | Yüksek7,5 | — | %17,0 | 28 Şub 2018 |
35İzleyin | CVE-2017-14050İstismar yok | In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contablackcat-cms · blackcat cms · CWE-434 | Yüksek8,8 | — | %1,2 | 31 Ağu 2017 |
35İzleyin | CVE-2017-14399İstismar yok | In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated byblackcat-cms · blackcat cms · CWE-434 | Yüksek8,8 | — | %1,0 | 12 Eyl 2017 |
35İzleyin | CVE-2017-14048İstismar yok | BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backblackcat-cms · blackcat cms · CWE-352 | Yüksek8,8 | — | %0,6 | 31 Ağu 2017 |
34İzleyin | CVE-2023-53892İstismar yok | Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Managerblackcat-cms · blackcat cms · CWE-434 | Yüksek8,6 | — | %0,9 | 15 Ara 2025 |
26İzleyin | CVE-2017-13670İstismar yok | In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonblackcat-cms · blackcat cms | Orta6,5 | — | %0,8 | 31 Ağu 2017 |
24İzleyin | CVE-2023-44043İstismar yok | A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web blackcat-cms · blackcat cms · CWE-79 | Orta6,1 | — | %0,6 | 27 Eyl 2023 |
21İzleyin | CVE-2017-9609Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via thblackcat-cms · blackcat cms · CWE-79 | Orta5,4 | — | %1,5 | 17 Tem 2017 |
21İzleyin | CVE-2017-14049İstismar yok | In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website headerblackcat-cms · blackcat cms · CWE-79 | Orta5,4 | — | %0,6 | 31 Ağu 2017 |
21İzleyin | CVE-2018-16635İstismar yok | Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.blackcat-cms · blackcat cms · CWE-79 | Orta5,4 | — | %0,6 | 10 Ara 2018 |
21İzleyin | CVE-2023-44042İstismar yok | A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scblackcat-cms · blackcat cms · CWE-79 | Orta5,4 | — | %0,5 | 27 Eyl 2023 |
21İzleyin | CVE-2020-25877İstismar yok | A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute blackcat-cms · blackcat cms · CWE-79 | Orta5,4 | — | %0,5 | 9 Tem 2021 |
20İzleyin | CVE-2023-53891İstismar yok | Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modificationblackcat-cms · blackcat cms · CWE-79 | Orta5,1 | — | %0,2 | 15 Ara 2025 |
19İzleyin | CVE-2018-10821Kavram kanıtı | Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin rolblackcat-cms · blackcat cms · CWE-79 | Orta4,8 | — | %1,0 | 14 Haz 2018 |
19İzleyin | CVE-2021-27237İstismar yok | The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.blackcat-cms · blackcat cms · CWE-79 | Orta4,8 | — | %1,0 | 16 Şub 2021 |
19İzleyin | CVE-2015-5521İstismar yok | Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name iblackcat-cms · blackcat cms · CWE-79 | Orta4,8 | — | %0,7 | 14 Tem 2015 |
19İzleyin | CVE-2020-25878İstismar yok | A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execublackcat-cms · blackcat cms · CWE-79 | Orta4,8 | — | %0,5 | 9 Tem 2021 |
18İzleyin | CVE-2014-5259İstismar yok | Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remoblackcat-cms · blackcat cms · CWE-79 | Orta4,3 | — | %2,0 | 12 Eyl 2014 |
- CVE-2020-2545337İzleyin
An issue was discovered in BlackCat CMS before 1.4.
YüksekCVSS 8,8Kavram kanıtıEPSS %6blackcat-cms · blackcat cms15 Eyl 2020
- CVE-2015-507935İzleyin
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a ..
YüksekCVSS 7,5Kavram kanıtıEPSS %17blackcat-cms · blackcat cms28 Şub 2018
- CVE-2017-1405035İzleyin
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that conta
YüksekCVSS 8,8İstismar yokEPSS %1blackcat-cms · blackcat cms31 Ağu 2017
- CVE-2017-1439935İzleyin
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by
YüksekCVSS 8,8İstismar yokEPSS %1blackcat-cms · blackcat cms12 Eyl 2017
- CVE-2017-1404835İzleyin
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to back
YüksekCVSS 8,8İstismar yokEPSS %1blackcat-cms · blackcat cms31 Ağu 2017
- CVE-2023-5389234İzleyin
Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager
YüksekCVSS 8,6İstismar yokEPSS %1blackcat-cms · blackcat cms15 Ara 2025
- CVE-2017-1367026İzleyin
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demon
OrtaCVSS 6,5İstismar yokEPSS %1blackcat-cms · blackcat cms31 Ağu 2017
- CVE-2023-4404324İzleyin
A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web
OrtaCVSS 6,1İstismar yokEPSS %1blackcat-cms · blackcat cms27 Eyl 2023
- CVE-2017-960921İzleyin
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via th
OrtaCVSS 5,4Kavram kanıtıEPSS %2blackcat-cms · blackcat cms17 Tem 2017
- CVE-2017-1404921İzleyin
In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header
OrtaCVSS 5,4İstismar yokEPSS %1blackcat-cms · blackcat cms31 Ağu 2017
- CVE-2018-1663521İzleyin
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
OrtaCVSS 5,4İstismar yokEPSS %1blackcat-cms · blackcat cms10 Ara 2018
- CVE-2023-4404221İzleyin
A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web sc
OrtaCVSS 5,4İstismar yokEPSS %1blackcat-cms · blackcat cms27 Eyl 2023
- CVE-2020-2587721İzleyin
A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute
OrtaCVSS 5,4İstismar yokEPSS %1blackcat-cms · blackcat cms9 Tem 2021
- CVE-2023-5389120İzleyin
Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification
OrtaCVSS 5,1İstismar yokEPSS %0blackcat-cms · blackcat cms15 Ara 2025
- CVE-2018-1082119İzleyin
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin rol
OrtaCVSS 4,8Kavram kanıtıEPSS %1blackcat-cms · blackcat cms14 Haz 2018
- CVE-2021-2723719İzleyin
The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.
OrtaCVSS 4,8İstismar yokEPSS %1blackcat-cms · blackcat cms16 Şub 2021
- CVE-2015-552119İzleyin
Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name i
OrtaCVSS 4,8İstismar yokEPSS %1blackcat-cms · blackcat cms14 Tem 2015
- CVE-2020-2587819İzleyin
A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execu
OrtaCVSS 4,8İstismar yokEPSS %1blackcat-cms · blackcat cms9 Tem 2021
- CVE-2014-525918İzleyin
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remo
OrtaCVSS 4,3İstismar yokEPSS %2blackcat-cms · blackcat cms12 Eyl 2014