CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ddsn 1Cm3 Acora Content Management System Sep 30, 2025 Feb 20, 2025 N/A· v4 6.0 MEDIUM· v3 N/A· v2 DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the...Show more |
1Ddsn 1Cm3 Acora Content Management System Oct 3, 2025 Jan 15, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attack...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) in the "l" parameter, which reveals the i...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx. |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attacke...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remot...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Apr 25, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to hijack the authentication of unspecifi...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Apr 25, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Apr 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote attackers to inject ar...Show more |