Aerocms Project
Aerocms Project Aerocms: vulnerabilidades y CVE
Aerocms Project Aerocms tiene 20 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-50895 | Alta (8.8) | 0.64% | — | 13 ene 2026 | Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query… |
| CVE-2023-29847 | Media (5.4) | 0.38% | — | 14 abr 2023 | AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute… |
| CVE-2022-46137 | Alta (7.5) | 1.4% | — | 16 dic 2022 | AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1. |
| CVE-2022-46135 | Alta (7.2) | 1.2% | — | 16 dic 2022 | In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server. |
| CVE-2022-46051 | Alta (7.2) | 0.86% | — | 13 dic 2022 | The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks. |
| CVE-2022-46059 | Media (6.5) | 0.33% | — | 13 dic 2022 | AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-46061 | Media (6.1) | 0.47% | — | 13 dic 2022 | AeroCMS v0.0.1 is vulnerable to ClickJacking. |
| CVE-2022-46058 | Media (4.8) | 0.46% | — | 13 dic 2022 | AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… |
| CVE-2022-46047 | Media (4.9) | 0.76% | — | 13 dic 2022 | AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter. |
| CVE-2022-45329 | Alta (7.5) | 0.79% | — | 29 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. |
| CVE-2022-45536 | Media (4.9) | 0.86% | — | 22 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information. |
| CVE-2022-45535 | Media (4.9) | 0.83% | — | 22 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information. |
| CVE-2022-45529 | Media (4.9) | 0.78% | — | 22 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information. |
| CVE-2022-45331 | Alta (7.5) | 0.81% | — | 22 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information. |
| CVE-2022-45330 | Alta (7.5) | 0.81% | — | 22 nov 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information. |
| CVE-2022-38305 | Alta (8.8) | 1.2% | — | 13 sept 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-38812 | Media (6.5) | 2.6% | — | 31 ago 2022 | AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |
| CVE-2022-27063 | Media (6.1) | 1.5% | — | 8 abr 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload… |
| CVE-2022-27062 | Media (4.8) | 1.1% | — | 8 abr 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected… |
| CVE-2022-27061 | Alta (7.2) | 2.7% | — | 8 abr 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.