Vulnerabilities (CVE)

Filtered by vendor Classcms Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25581 1 Classcms 1 Classcms 2024-11-21 6.8 MEDIUM 7.8 HIGH
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.
CVE-2024-8144 1 Classcms 1 Classcms 2024-09-18 4.0 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-8145 1 Classcms 1 Classcms 2024-09-18 3.3 LOW 4.8 MEDIUM
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.