← Back

Sunlight Cms

sunlight_cms

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Sunlight Cms
sunlight_cms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sunlight Cms
1Sunlight Cms
Jun 17, 2026
Jan 27, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.
1Sunlight Cms
1Sunlight Cms
Jun 17, 2026
Jan 27, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.
1Sunlight Cms
1Sunlight Cms
Apr 9, 2025
May 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.