← Back

Holacms

holacms

Vendor: Hola • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hola
1Holacms
Apr 16, 2026
Mar 14, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.