Products: 1
Vulnerabilities: 12
Known Exploited: 0
1
Critical Level Threats
4
High Level Threats
7
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-3786
EasyCMS Request Parameter RbacuserAction.class.php sql injection
Last Modified: Apr 16, 2026
Published: Mar 08, 2026
CVE-2026-3785
EasyCMS Request Parameter RbacnodeAction.class.php sql injection
Last Modified: Apr 16, 2026
Published: Mar 08, 2026
CVE-2026-1105
EasyCMS UserAction.class.php sql injection
Last Modified: Apr 18, 2026
Published: Jan 17, 2026
CVE-2022-23358
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
Last Modified: Nov 21, 2024
Published: Feb 16, 2022
CVE-2020-24271
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
Last Modified: Nov 21, 2024
Published: Feb 01, 2021
Items Per Page
