← Back

Classcms Project

classcms_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Classcms
classcms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Classcms Project
1Classcms
Nov 21, 2024
Jul 20, 2024
5.3 MEDIUM· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation...Show more
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271987.Show less
1Classcms Project
1Classcms
Apr 15, 2025
Dec 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
1Classcms Project
1Classcms
Nov 21, 2024
Mar 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field.