Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Frogcms Project Subscribe
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25872 1 Frogcms Project 1 Frogcms 2021-11-03 4.0 MEDIUM 4.9 MEDIUM
A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.
CVE-2021-26794 1 Frogcms Project 1 Frogcms 2021-09-29 7.5 HIGH 9.8 CRITICAL
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
CVE-2018-10806 1 Frogcms Project 1 Frogcms 2020-08-24 3.5 LOW 5.4 MEDIUM
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.
CVE-2018-19844 1 Frogcms Project 1 Frogcms 2019-02-25 3.5 LOW 4.8 MEDIUM
FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319.
CVE-2018-16447 1 Frogcms Project 1 Frogcms 2019-02-25 6.8 MEDIUM 8.8 HIGH
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
CVE-2018-10570 1 Frogcms Project 1 Frogcms 2018-06-07 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
CVE-2018-10318 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
CVE-2018-10321 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
CVE-2018-10320 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
CVE-2018-10319 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.