Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Frog Cms Project Subscribe
Total 18 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-1010235 1 Frog Cms Project 1 Frog Cms 2019-07-23 3.5 LOW 5.4 MEDIUM
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.
CVE-2018-20448 1 Frog Cms Project 1 Frog Cms 2019-03-04 3.5 LOW 5.4 MEDIUM
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
CVE-2018-20775 1 Frog Cms Project 1 Frog Cms 2019-02-11 6.5 MEDIUM 7.2 HIGH
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
CVE-2018-20776 1 Frog Cms Project 1 Frog Cms 2019-02-11 5.0 MEDIUM 7.5 HIGH
Frog CMS 0.9.5 provides a directory listing for a /public request.
CVE-2018-20773 1 Frog Cms Project 1 Frog Cms 2019-02-11 6.5 MEDIUM 7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
CVE-2018-20778 1 Frog Cms Project 1 Frog Cms 2019-02-11 4.3 MEDIUM 6.1 MEDIUM
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
CVE-2018-20772 1 Frog Cms Project 1 Frog Cms 2019-02-11 6.5 MEDIUM 7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
CVE-2018-20774 1 Frog Cms Project 1 Frog Cms 2019-02-11 3.5 LOW 5.4 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
CVE-2018-20777 1 Frog Cms Project 1 Frog Cms 2019-02-11 3.5 LOW 5.4 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
CVE-2019-6243 1 Frog Cms Project 1 Frog Cms 2019-01-16 4.3 MEDIUM 6.1 MEDIUM
Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).
CVE-2018-20680 1 Frog Cms Project 1 Frog Cms 2019-01-11 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.
CVE-2018-16373 1 Frog Cms Project 1 Frog Cms 2018-10-24 4.0 MEDIUM 4.9 MEDIUM
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.
CVE-2018-16374 1 Frog Cms Project 1 Frog Cms 2018-10-24 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.
CVE-2018-11098 1 Frog Cms Project 1 Frog Cms 2018-06-19 6.5 MEDIUM 7.2 HIGH
An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.
CVE-2018-9992 1 Frog Cms Project 1 Frog Cms 2018-05-11 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.
CVE-2018-9991 1 Frog Cms Project 1 Frog Cms 2018-05-11 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
CVE-2018-8908 1 Frog Cms Project 1 Frog Cms 2018-05-09 6.8 MEDIUM 8.8 HIGH
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.
CVE-2014-4912 1 Frog Cms Project 1 Frog Cms 2018-04-18 7.5 HIGH 9.8 CRITICAL
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.