← Back

Espcms

espcms

Vendor: Ecisp • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ecisp
1Espcms
Nov 21, 2024
Jun 27, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.
1Ecisp
1Espcms
Mar 18, 2025
Feb 17, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
1Ecisp
1Espcms
May 1, 2025
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
1Ecisp
1Espcms
May 1, 2025
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
1Ecisp
1Espcms
May 1, 2025
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.