Articlecms Project
Articlecms Project Articlecms: vulnerabilities and CVEs
Articlecms Project Articlecms has 4 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28063 | Critical (9.8) | 1.3% | — | May 13, 2021 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. |
| CVE-2020-20092 | Critical (9.8) | 1.3% | — | May 13, 2021 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user… |
| CVE-2018-19469 | Medium (6.1) | 0.64% | — | Nov 23, 2018 | ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. |
| CVE-2018-12339 | Medium (5.4) | 0.48% | — | Jun 13, 2018 | ArticleCMS through 2017-02-19 has XSS via an "add an article" action. |