Genixcms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 18
    Known Exploited: 0
    1
    Critical Level Threats
    6
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2017-14740

    Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.

    Last Modified: Nov 21, 2024
    Published: Apr 26, 2018

    CVE-2017-17431

    GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.

    Last Modified: Apr 20, 2025
    Published: Dec 05, 2017

    CVE-2017-14763

    In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.

    Last Modified: Apr 20, 2025
    Published: Sep 27, 2017

    CVE-2017-14761

    In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.

    Last Modified: Apr 20, 2025
    Published: Sep 27, 2017

    CVE-2017-14765

    In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.

    Last Modified: Apr 20, 2025
    Published: Sep 27, 2017
    Items Per Page
    Genixcms Vulnerabilities & Security CVEs | CVE-DB