← Back

Enanocms

enanocms

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Enano Cms
enano_cms
Enanocms
enanocms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Enanocms
1Enano Cms
Apr 29, 2026
Apr 7, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation pat...Show more
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.Show less
1Enanocms
1Enano Cms
Apr 29, 2026
Apr 7, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbi...Show more
SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.Show less
1Enanocms
1Enanocms
Apr 29, 2026
Feb 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the comment submission interface (includes/comment.php) in Enano CMS before 1.0.6pl1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.