Vulnerabilities (CVE)

Filtered by vendor S-cms Subscribe
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18427 1 S-cms 1 S-cms 2023-12-10 7.5 HIGH 9.8 CRITICAL
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
CVE-2018-18426 1 S-cms 1 S-cms 2023-12-10 9.0 HIGH 8.8 HIGH
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.