Dswjcms Project
Dswjcms Project Dswjcms: vulnerabilities and CVEs
Dswjcms Project Dswjcms has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19268 | Medium (5.7) | 0.31% | — | Sep 9, 2021 | A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users. |
| CVE-2020-19267 | Critical (9.8) | 1.6% | — | Sep 9, 2021 | An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. |
| CVE-2020-19266 | Medium (6.1) | 0.64% | — | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. |
| CVE-2020-19265 | Medium (6.1) | 0.64% | — | Sep 9, 2021 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. |