foxcms kayıtları
foxcms üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2025-29306Kavram kanıtı | An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.foxcms · foxcms · CWE-94 | Kritik9,8 | — | %46,6 | 27 Mar 2025 |
39İzleyin | CVE-2025-25789İstismar yok | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.foxcms · foxcms · CWE-94 | Kritik9,8 | — | %1,3 | 26 Şub 2025 |
39İzleyin | CVE-2025-25790İstismar yok | An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitraryfoxcms · foxcms · CWE-434 | Kritik9,8 | — | %0,9 | 26 Şub 2025 |
39İzleyin | CVE-2025-50692İstismar yok | FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.foxcms · foxcms · CWE-94 | Kritik9,8 | — | %0,7 | 7 Ağu 2025 |
35İzleyin | CVE-2025-55420İstismar yok | A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.foxcms · foxcms · CWE-79 | Yüksek8,8 | — | %0,5 | 21 Ağu 2025 |
35İzleyin | CVE-2025-55409İstismar yok | FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.foxcms · foxcms · CWE-79 | Yüksek8,8 | — | %0,5 | 25 Ağu 2025 |
35İzleyin | CVE-2025-55422İstismar yok | In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.foxcms · foxcms · CWE-79 | Yüksek8,8 | — | %0,4 | 27 Ağu 2025 |
33İzleyin | CVE-2025-46154İstismar yok | Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.foxcms · foxcms · CWE-89 | Yüksek8,4 | — | %0,2 | 3 Haz 2025 |
29İzleyin | CVE-2025-56630İstismar yok | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.foxcms · foxcms · CWE-89 | Yüksek7,3 | — | %0,2 | 8 Eyl 2025 |
28İzleyin | CVE-2025-29181İstismar yok | FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.foxcms · foxcms · CWE-89 | Yüksek7,2 | — | %0,4 | 17 Nis 2025 |
28İzleyin | CVE-2025-29180İstismar yok | In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.foxcms · foxcms · CWE-89 | Yüksek7,2 | — | %0,4 | 17 Nis 2025 |
21İzleyin | CVE-2025-5155İstismar yok | qianfox FoxCMS Article.php batchCope sql injectionfoxcms · foxcms · CWE-74 | Orta5,3 | — | %0,5 | 25 May 2025 |
21İzleyin | CVE-2025-56435İstismar yok | SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.foxcms · foxcms · CWE-89 | Orta5,3 | — | %0,4 | 3 Eyl 2025 |
8İzleyin | CVE-2025-10251İstismar yok | FoxCMS Images.php batchCope sql injectionfoxcms · foxcms · CWE-74 | Düşük2,1 | — | %0,4 | 11 Eyl 2025 |
7İzleyin | CVE-2025-12920İstismar yok | qianfox FoxCMS Product.php edit cross site scriptingfoxcms · foxcms · CWE-79 | Düşük1,9 | — | %0,3 | 9 Kas 2025 |
- CVE-2025-2930653Planlayın
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
KritikCVSS 9,8Kavram kanıtıEPSS %47foxcms · foxcms27 Mar 2025
- CVE-2025-2578939İzleyin
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
KritikCVSS 9,8İstismar yokEPSS %1foxcms · foxcms26 Şub 2025
- CVE-2025-2579039İzleyin
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary
KritikCVSS 9,8İstismar yokEPSS %1foxcms · foxcms26 Şub 2025
- CVE-2025-5069239İzleyin
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
KritikCVSS 9,8İstismar yokEPSS %1foxcms · foxcms7 Ağu 2025
- CVE-2025-5542035İzleyin
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.
YüksekCVSS 8,8İstismar yokEPSS %0foxcms · foxcms21 Ağu 2025
- CVE-2025-5540935İzleyin
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.
YüksekCVSS 8,8İstismar yokEPSS %0foxcms · foxcms25 Ağu 2025
- CVE-2025-5542235İzleyin
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
YüksekCVSS 8,8İstismar yokEPSS %0foxcms · foxcms27 Ağu 2025
- CVE-2025-4615433İzleyin
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
YüksekCVSS 8,4İstismar yokEPSS %0foxcms · foxcms3 Haz 2025
- CVE-2025-5663029İzleyin
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.
YüksekCVSS 7,3İstismar yokEPSS %0foxcms · foxcms8 Eyl 2025
- CVE-2025-2918128İzleyin
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
YüksekCVSS 7,2İstismar yokEPSS %0foxcms · foxcms17 Nis 2025
- CVE-2025-2918028İzleyin
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability.
YüksekCVSS 7,2İstismar yokEPSS %0foxcms · foxcms17 Nis 2025
- CVE-2025-515521İzleyin
qianfox FoxCMS Article.php batchCope sql injection
OrtaCVSS 5,3İstismar yokEPSS %0foxcms · foxcms25 May 2025
- CVE-2025-5643521İzleyin
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.
OrtaCVSS 5,3İstismar yokEPSS %0foxcms · foxcms3 Eyl 2025
- CVE-2025-102518İzleyin
FoxCMS Images.php batchCope sql injection
DüşükCVSS 2,1İstismar yokEPSS %0foxcms · foxcms11 Eyl 2025
- CVE-2025-129207İzleyin
qianfox FoxCMS Product.php edit cross site scripting
DüşükCVSS 1,9İstismar yokEPSS %0foxcms · foxcms9 Kas 2025