Home/Product/5none nonecms
Product

5none nonecms

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-18282
all versions
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedb
6.1MEDIUM
CVE-2020-18647
all versions
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor"
7.5HIGH
CVE-2020-18646
all versions
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.ph
7.5HIGH
CVE-2020-23376
all versions
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which
6.1MEDIUM
CVE-2020-23374
all versions
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inje
5.4MEDIUM
CVE-2020-23373
all versions
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject a
5.4MEDIUM
CVE-2020-23371
all versions
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 a
6.1MEDIUM
CVE-2019-16721
all versions
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
6.5MEDIUM
CVE-2018-20062
all versions
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via
9.8CRITICAL
CVE-2018-7219
all versions
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an accou
8.8HIGH
CVE-2018-6029
all versions
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of in
7.5HIGH
CVE-2018-6022
<= 1.3.0
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated us
6.5MEDIUM