Vulnerabilities (CVE)

Filtered by vendor S-cms Subscribe
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-6805 1 S-cms 1 S-cms 2024-02-28 7.5 HIGH 9.8 CRITICAL
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
CVE-2018-20478 1 S-cms 1 S-cms 2024-02-28 5.0 MEDIUM 7.5 HIGH
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.