İçeriğe atla
Noroxi

blackcat-cms kayıtları

blackcat-cms üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2020-25453
    37İzleyin

    An issue was discovered in BlackCat CMS before 1.4.

    YüksekCVSS 8,8Kavram kanıtıEPSS %6

    blackcat-cms · blackcat cms15 Eyl 2020

  • CVE-2015-5079
    35İzleyin

    Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a ..

    YüksekCVSS 7,5Kavram kanıtıEPSS %17

    blackcat-cms · blackcat cms28 Şub 2018

  • CVE-2017-14050
    35İzleyin

    In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that conta

    YüksekCVSS 8,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms31 Ağu 2017

  • CVE-2017-14399
    35İzleyin

    In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by

    YüksekCVSS 8,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms12 Eyl 2017

  • CVE-2017-14048
    35İzleyin

    BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to back

    YüksekCVSS 8,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms31 Ağu 2017

  • CVE-2023-53892
    34İzleyin

    Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager

    YüksekCVSS 8,6İstismar yokEPSS %1

    blackcat-cms · blackcat cms15 Ara 2025

  • CVE-2017-13670
    26İzleyin

    In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demon

    OrtaCVSS 6,5İstismar yokEPSS %1

    blackcat-cms · blackcat cms31 Ağu 2017

  • CVE-2023-44043
    24İzleyin

    A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web

    OrtaCVSS 6,1İstismar yokEPSS %1

    blackcat-cms · blackcat cms27 Eyl 2023

  • CVE-2017-9609
    21İzleyin

    Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via th

    OrtaCVSS 5,4Kavram kanıtıEPSS %2

    blackcat-cms · blackcat cms17 Tem 2017

  • CVE-2017-14049
    21İzleyin

    In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header

    OrtaCVSS 5,4İstismar yokEPSS %1

    blackcat-cms · blackcat cms31 Ağu 2017

  • CVE-2018-16635
    21İzleyin

    Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.

    OrtaCVSS 5,4İstismar yokEPSS %1

    blackcat-cms · blackcat cms10 Ara 2018

  • CVE-2023-44042
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web sc

    OrtaCVSS 5,4İstismar yokEPSS %1

    blackcat-cms · blackcat cms27 Eyl 2023

  • CVE-2020-25877
    21İzleyin

    A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute

    OrtaCVSS 5,4İstismar yokEPSS %1

    blackcat-cms · blackcat cms9 Tem 2021

  • CVE-2023-53891
    20İzleyin

    Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification

    OrtaCVSS 5,1İstismar yokEPSS %0

    blackcat-cms · blackcat cms15 Ara 2025

  • CVE-2018-10821
    19İzleyin

    Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin rol

    OrtaCVSS 4,8Kavram kanıtıEPSS %1

    blackcat-cms · blackcat cms14 Haz 2018

  • CVE-2021-27237
    19İzleyin

    The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.

    OrtaCVSS 4,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms16 Şub 2021

  • CVE-2015-5521
    19İzleyin

    Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name i

    OrtaCVSS 4,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms14 Tem 2015

  • CVE-2020-25878
    19İzleyin

    A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execu

    OrtaCVSS 4,8İstismar yokEPSS %1

    blackcat-cms · blackcat cms9 Tem 2021

  • CVE-2014-5259
    18İzleyin

    Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remo

    OrtaCVSS 4,3İstismar yokEPSS %2

    blackcat-cms · blackcat cms12 Eyl 2014