Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-8438

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019

    CVE-2019-8439

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019

    CVE-2019-8440

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_logo.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019

    CVE-2018-19291

    An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.

    Last Modified: Nov 21, 2024
    Published: Nov 15, 2018

    CVE-2018-18209

    XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.

    Last Modified: Nov 21, 2024
    Published: Oct 10, 2018
    Items Per Page
    Dilicms Vulnerabilities & Security CVEs | CVE-DB