← Back

Cmswing

cmswing

8 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cmswing
cmswing

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmswing
1Cmswing
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
1Cmswing
1Cmswing
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
1Cmswing
1Cmswing
Jun 17, 2026
May 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.
1Cmswing
1Cmswing
Jun 17, 2026
May 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.