CVEs (18)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted U...Show more |
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the...Show more |
1Victor Cms Project 1Victor Cms Feb 10, 2026 Feb 3, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the c...Show more |
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execu...Show more |
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Jun 16, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Apr 28, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Mar 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Feb 3, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Jan 31, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name,...Show more |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Jan 31, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Jul 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Oct 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Jul 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Sep 10, 2018 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. |
1Victor Cms Project 1Victor Cms Nov 21, 2024 Aug 21, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen. |