Metalgenix

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 18
    Known Exploited: 0
    6
    Critical Level Threats
    6
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-24563

    In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.

    Last Modified: Nov 21, 2024
    Published: Mar 03, 2022

    CVE-2020-10057

    GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.

    Last Modified: Nov 21, 2024
    Published: Mar 04, 2020

    CVE-2018-14476

    GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.

    Last Modified: Nov 21, 2024
    Published: Dec 31, 2019

    CVE-2015-3933

    Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.

    Last Modified: Apr 20, 2025
    Published: Nov 08, 2017

    CVE-2017-5959

    CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.

    Last Modified: Apr 20, 2025
    Published: Feb 21, 2017
    Items Per Page