← Back

Victoralagwu

victoralagwu

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cmssite
cmssite

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Victoralagwu
1Cmssite
Apr 17, 2026
Apr 12, 2026
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php...Show more
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and credentials.Show less
1Victoralagwu
1Cmssite
Apr 9, 2026
Apr 5, 2026
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into...Show more
CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.Show less
1Victoralagwu
1Cmssite
Apr 9, 2026
Apr 5, 2026
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php wit...Show more
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.Show less