← Back

Frogcms Project

frogcms_project

24 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Frogcms
frogcms

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frogcms Project
1Frogcms
Sep 25, 2024
Sep 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
1Frogcms Project
1Frogcms
Sep 25, 2024
Sep 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
1Frogcms Project
1Frogcms
Apr 28, 2025
Sep 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
1Frogcms Project
1Frogcms
Apr 28, 2025
Sep 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add
1Frogcms Project
1Frogcms
Aug 15, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.
1Frogcms Project
1Frogcms
Aug 13, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
1Frogcms Project
1Frogcms
Aug 15, 2024
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.
1Frogcms Project
1Frogcms
Jun 17, 2026
Oct 29, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.
1Frogcms Project
1Frogcms
Jun 17, 2026
Sep 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
1Frogcms Project
1Frogcms
Nov 21, 2024
Dec 31, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319.
1Frogcms Project
1Frogcms
Nov 21, 2024
Sep 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
1Frogcms Project
1Frogcms
Nov 21, 2024
May 8, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with...Show more
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.Show less
1Frogcms Project
1Frogcms
Nov 21, 2024
Apr 30, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.