İçeriğe atla
Noroxi

foxcms kayıtları

foxcms üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2025-29306
    53Planlayın

    An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    foxcms · foxcms27 Mar 2025

  • CVE-2025-25789
    39İzleyin

    FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    foxcms · foxcms26 Şub 2025

  • CVE-2025-25790
    39İzleyin

    An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary

    KritikCVSS 9,8İstismar yokEPSS %1

    foxcms · foxcms26 Şub 2025

  • CVE-2025-50692
    39İzleyin

    FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

    KritikCVSS 9,8İstismar yokEPSS %1

    foxcms · foxcms7 Ağu 2025

  • CVE-2025-55420
    35İzleyin

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.

    YüksekCVSS 8,8İstismar yokEPSS %0

    foxcms · foxcms21 Ağu 2025

  • CVE-2025-55409
    35İzleyin

    FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.

    YüksekCVSS 8,8İstismar yokEPSS %0

    foxcms · foxcms25 Ağu 2025

  • CVE-2025-55422
    35İzleyin

    In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

    YüksekCVSS 8,8İstismar yokEPSS %0

    foxcms · foxcms27 Ağu 2025

  • CVE-2025-46154
    33İzleyin

    Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

    YüksekCVSS 8,4İstismar yokEPSS %0

    foxcms · foxcms3 Haz 2025

  • CVE-2025-56630
    29İzleyin

    FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

    YüksekCVSS 7,3İstismar yokEPSS %0

    foxcms · foxcms8 Eyl 2025

  • CVE-2025-29181
    28İzleyin

    FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

    YüksekCVSS 7,2İstismar yokEPSS %0

    foxcms · foxcms17 Nis 2025

  • CVE-2025-29180
    28İzleyin

    In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.

    YüksekCVSS 7,2İstismar yokEPSS %0

    foxcms · foxcms17 Nis 2025

  • CVE-2025-5155
    21İzleyin

    qianfox FoxCMS Article.php batchCope sql injection

    OrtaCVSS 5,3İstismar yokEPSS %0

    foxcms · foxcms25 May 2025

  • CVE-2025-56435
    21İzleyin

    SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.

    OrtaCVSS 5,3İstismar yokEPSS %0

    foxcms · foxcms3 Eyl 2025

  • FoxCMS Images.php batchCope sql injection

    DüşükCVSS 2,1İstismar yokEPSS %0

    foxcms · foxcms11 Eyl 2025

  • qianfox FoxCMS Product.php edit cross site scripting

    DüşükCVSS 1,9İstismar yokEPSS %0

    foxcms · foxcms9 Kas 2025