Product
cuppacms
25 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-47990
CVE-2023-39681
CVE-2021-29368
CVE-2022-37191
CVE-2022-37190
CVE-2022-38296
CVE-2022-38295
CVE-2022-34121
CVE-2022-27985
CVE-2022-27984
CVE-2022-25498
CVE-2022-25497
CVE-2022-25495
CVE-2022-25486
CVE-2022-25485
CVE-2022-25401
CVE-2022-24647
CVE-2022-24266
CVE-2022-24265
CVE-2022-24264
CVE-2021-3376
CVE-2020-26048
CVE-2018-19918
CVE-2018-19559
CVE-2018-17300
all versions
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitra
all versions
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configur
<= 2019-11-12
Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attack
all versions
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted
all versions
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function)
all versions
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
all versions
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerab
all versions
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/wind
all versions
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
all versions
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/de
all versions
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/aj
all versions
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
all versions
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arb
all versions
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
all versions
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
all versions
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers
all versions
Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
all versions
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_b
all versions
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/m
all versions
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_
< 31\/jan\/2021
An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a
< 2019-11-12
The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image
all versions
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
< 2018-11-12
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
< 2018-09-04
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.