Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-50565

    A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Last Modified: Nov 26, 2024
    Published: Dec 14, 2023

    CVE-2022-41473

    RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

    Last Modified: May 15, 2025
    Published: Oct 13, 2022

    CVE-2022-41474

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.

    Last Modified: May 15, 2025
    Published: Oct 13, 2022

    CVE-2022-41475

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.

    Last Modified: May 15, 2025
    Published: Oct 13, 2022

    CVE-2021-37394

    In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.

    Last Modified: Nov 21, 2024
    Published: Jul 26, 2021
    Items Per Page
    Rpcms Vulnerabilities & Security CVEs | CVE-DB