Vulnerabilities (CVE)

Filtered by vendor Aerocms Project Subscribe
Filtered by product Aerocms
Total 19 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-29847 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 5.4 MEDIUM
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-46137 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.5 HIGH
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.
CVE-2022-45536 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
CVE-2022-45329 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
CVE-2022-45529 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
CVE-2022-46135 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.2 HIGH
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.
CVE-2022-45330 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
CVE-2022-46051 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.2 HIGH
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.
CVE-2022-46047 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 4.9 MEDIUM
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
CVE-2022-46059 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 6.5 MEDIUM
AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-46061 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 6.1 MEDIUM
AeroCMS v0.0.1 is vulnerable to ClickJacking.
CVE-2022-45331 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
CVE-2022-45535 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
CVE-2022-46058 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 4.8 MEDIUM
AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
CVE-2022-38305 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 8.8 HIGH
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-38812 1 Aerocms Project 1 Aerocms 2023-12-10 N/A 6.5 MEDIUM
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CVE-2022-27063 1 Aerocms Project 1 Aerocms 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
CVE-2022-27061 1 Aerocms Project 1 Aerocms 2023-12-10 6.5 MEDIUM 7.2 HIGH
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27062 1 Aerocms Project 1 Aerocms 2023-12-10 3.5 LOW 4.8 MEDIUM
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.