Ionizecms
Ionizecms Ionize: vulnerabilities and CVEs
Ionizecms Ionize has 4 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29307 | Critical (9.8) | 18% | — | May 12, 2022 | IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. |
| CVE-2022-29306 | Critical (9.8) | 1.1% | — | May 12, 2022 | IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php. |
| CVE-2022-26272 | Critical (9.8) | 22% | — | Mar 24, 2022 | A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php. |
| CVE-2017-5961 | Medium (6.1) | 0.98% | — | Feb 12, 2017 | An issue was discovered in ionize through 1.0.8. The vulnerability exists due to insufficient filtration of user-supplied data in the "path" HTTP GET parameter passed to the… |