← Back

Daicuo

daicuo

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Daicuo
daicuo

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Daicuo
1Daicuo
Oct 23, 2025
Oct 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
1Daicuo
1Daicuo
Oct 23, 2025
Oct 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
1Daicuo
1Daicuo
Apr 29, 2026
Jun 29, 2025
2.1 LOW· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possibl...Show more
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Daicuo
1Daicuo
Jun 23, 2025
Apr 18, 2025
4.8 MEDIUM· v4
3.4 LOW· v3
3.3 LOW· v2
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site...Show more
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Daicuo
1Daicuo
Nov 21, 2024
Dec 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.