Product
aerocms project aerocms
20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-50895
CVE-2023-29847
CVE-2022-46137
CVE-2022-46135
CVE-2022-46051
CVE-2022-46059
CVE-2022-46061
CVE-2022-46058
CVE-2022-46047
CVE-2022-45329
CVE-2022-45536
CVE-2022-45535
CVE-2022-45529
CVE-2022-45331
CVE-2022-45330
CVE-2022-38305
CVE-2022-38812
CVE-2022-27063
CVE-2022-27062
CVE-2022-27061
all versions
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries
all versions
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and com
all versions
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroC
all versions
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upl
all versions
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.
all versions
AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
all versions
AeroCMS v0.0.1 is vulnerable to ClickJacking.
all versions
AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows at
all versions
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attacke
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vuln
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulne
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability all
all versions
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerabi
all versions
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnera
all versions
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
all versions
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnera
all versions
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability al
all versions
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel.