CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Articlecms Project 1Articlecms Jun 17, 2026 May 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. |
1Articlecms Project 1Articlecms Jun 17, 2026 May 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execu...Show more |
1Articlecms Project 1Articlecms Nov 21, 2024 Nov 23, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. |
1Articlecms Project 1Articlecms Nov 21, 2024 Jun 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ArticleCMS through 2017-02-19 has XSS via an "add an article" action. |