Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: finecms-project Clear
ID Title
CVE-2017-14195 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14195)
cross-site scripting in finecms-project (CVE-2017-14195). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
CVE-2017-14194 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14194)
cross-site scripting in finecms-project (CVE-2017-14194). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
CVE-2017-14193 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14193)
cross-site scripting in finecms-project (CVE-2017-14193). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
CVE-2017-14192 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-14192)
cross-site scripting in finecms-project (CVE-2017-14192). Risk of unauthorized operations or information disclosure.
CVE-2017-13697 controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
CVE-2017-12774 SQL Injection in finecms-project (CVE-2017-12774)
SQL injection in finecms-project (CVE-2017-12774). Successful exploitation can lead to full system takeover.
CVE-2017-11198 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11198)
cross-site scripting in finecms-project (CVE-2017-11198). Risk of unauthorized operations or information disclosure.
CVE-2017-11202 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11202)
cross-site scripting in finecms-project (CVE-2017-11202). Risk of unauthorized operations or information disclosure.
CVE-2017-11201 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11201)
cross-site scripting in finecms-project (CVE-2017-11201). Risk of unauthorized operations or information disclosure.
CVE-2017-11200 SQL Injection in sqli (CVE-2017-11200)
SQL injection in sqli (CVE-2017-11200). Successful exploitation can lead to full system takeover.
CVE-2017-11167 Code Injection in finecms-project (CVE-2017-11167)
code injection in finecms-project (CVE-2017-11167). Successful exploitation can lead to full system takeover.
CVE-2017-11180 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11180)
cross-site scripting in finecms-project (CVE-2017-11180). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
CVE-2017-11179 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-11179)
cross-site scripting in finecms-project (CVE-2017-11179). Risk of unauthorized operations or information disclosure.
CVE-2017-10968 Code Injection in finecms-project (CVE-2017-10968)
code injection in finecms-project (CVE-2017-10968). Successful exploitation can lead to full system takeover.
CVE-2017-10973 SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-10973)
SSRF in ssrf (CVE-2017-10973). Data can be tampered with by attackers. Exploitable via `Host header`.
CVE-2017-10967 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-10967)
cross-site scripting in finecms-project (CVE-2017-10967). Risk of unauthorized operations or information disclosure.
CVE-2017-9252 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-9252)
cross-site scripting in finecms-project (CVE-2017-9252). Risk of unauthorized operations or information disclosure.
CVE-2017-9251 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-9251)
cross-site scripting in finecms-project (CVE-2017-9251). Risk of unauthorized operations or information disclosure.
CVE-2017-6511 Cross-Site Scripting (XSS) in finecms-project (CVE-2017-6511)
cross-site scripting in finecms-project (CVE-2017-6511). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →