« Back to list

Thecosy

Thecosy Icecms: vulnerabilities and CVEs

Thecosy Icecms has 20 published vulnerabilities, 0 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs20
Last 12 months0
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-22984High (7.5)0.50%—Jan 14, 2025
An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
CVE-2025-22983High (7.5)0.50%—Jan 14, 2025
An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
CVE-2024-48202Critical (9.8)0.64%—Oct 30, 2024
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
CVE-2024-46612Critical (9.8)0.63%—Sep 25, 2024
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
CVE-2024-46610High (7.5)0.47%—Sep 25, 2024
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the…
CVE-2024-46609High (7.5)0.67%—Sep 25, 2024
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
CVE-2024-46607High (7.6)0.52%—Sep 25, 2024
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
CVE-2023-6762Medium (4.3)0.69%—Dec 13, 2023
A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to…
CVE-2023-6761High (8.8)0.79%—Dec 13, 2023
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper…
CVE-2023-6760Medium (5.4)0.64%—Dec 13, 2023
A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit…
CVE-2023-6759High (7.5)0.97%—Dec 13, 2023
A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper…
CVE-2023-6758Medium (4.3)0.74%—Dec 13, 2023
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads…
CVE-2023-6757Medium (6.5)0.98%—Dec 13, 2023
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /adplanet/PlanetUser of the component API. The manipulation…
CVE-2023-6756Critical (9.8)1.3%—Dec 13, 2023
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper…
CVE-2023-6467Low (3.7)0.62%—Dec 2, 2023
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /Websquare/likeClickComment/ of the component Comment Like Handler. The…
CVE-2023-6466Medium (6.1)0.61%—Dec 2, 2023
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file /planet of the component User Comment Handler. The manipulation leads to cross…
CVE-2023-6438Medium (5.3)0.70%—Nov 30, 2023
A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper…
CVE-2023-40833Critical (9.8)0.72%—Oct 12, 2023
An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.
CVE-2023-33356Medium (5.4)0.38%—May 25, 2023
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33355High (7.5)0.61%—May 25, 2023
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.