Products: 5
    Vulnerabilities: 34
    Known Exploited: 0
    1
    Critical Level Threats
    16
    High Level Threats
    16
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-2852

    Cross-site scripting (XSS) vulnerability in modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1, when the Headlines module is enabled, allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Last Modified: Apr 11, 2025
    Published: Jul 23, 2010

    CVE-2009-3814

    Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.

    Last Modified: Apr 23, 2026
    Published: Oct 27, 2009

    CVE-2009-3813

    Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.

    Last Modified: Apr 23, 2026
    Published: Oct 27, 2009

    CVE-2009-3815

    RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to modules/contact/index.php or (2) uid[] parameter to userinfo.php, which leaks the installation path in an error message when these parameters are used in a call to the preg_match function.

    Last Modified: Apr 23, 2026
    Published: Oct 27, 2009

    CVE-2009-3804

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.

    Last Modified: Apr 23, 2026
    Published: Oct 27, 2009
    Items Per Page
    Runcms Vulnerabilities & Security CVEs | CVE-DB