Products: 2
Vulnerabilities: 5
Known Exploited: 0
1
Critical Level Threats
0
High Level Threats
3
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2024-48341
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop
Last Modified: Sep 18, 2025
Published: Sep 08, 2025
CVE-2025-28100
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
Last Modified: Apr 22, 2025
Published: Apr 15, 2025
CVE-2024-50651
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
Last Modified: Nov 27, 2024
Published: Nov 15, 2024
CVE-2024-50652
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.
Last Modified: Nov 22, 2024
Published: Nov 15, 2024
CVE-2024-8302
dingfanzu CMS chpwd.php sql injection
Last Modified: Sep 19, 2024
Published: Aug 29, 2024
Items Per Page
