Clippercms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-41495

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

    Last Modified: May 15, 2025
    Published: Oct 13, 2022

    CVE-2022-41497

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

    Last Modified: May 15, 2025
    Published: Oct 13, 2022

    CVE-2018-12101

    CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.

    Last Modified: Nov 21, 2024
    Published: Aug 15, 2019

    CVE-2018-19424

    ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

    Last Modified: Nov 21, 2024
    Published: Nov 21, 2018

    CVE-2018-19135

    ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.

    Last Modified: Nov 21, 2024
    Published: Nov 11, 2018
    Items Per Page
    Clippercms Vulnerabilities & Security CVEs | CVE-DB