← Back

Slimcms

slimcms

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Slimcms
slimcms

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Slimcms
1Slimcms
Apr 23, 2026
Dec 24, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
1Slimcms
1Slimcms
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.