Home/Product/s cms s cms
Product

s cms s cms

48 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-29962
all versions
S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
6.5MEDIUM
CVE-2023-7191
all versions
A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown pa
5.5MEDIUM
CVE-2023-7190
all versions
A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issu
5.5MEDIUM
CVE-2023-7189
all versions
A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an u
5.5MEDIUM
CVE-2023-51052
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.
9.8CRITICAL
CVE-2023-51051
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.
9.8CRITICAL
CVE-2023-51050
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.
9.8CRITICAL
CVE-2023-51049
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
9.8CRITICAL
CVE-2023-51048
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
9.8CRITICAL
CVE-2023-29963
all versions
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
7.2HIGH
CVE-2022-4377
all versions
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an u
3.5LOW
CVE-2022-23336
all versions
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
9.8CRITICAL
CVE-2020-20426
all versions
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
6.1MEDIUM
CVE-2020-20425
all versions
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
6.1MEDIUM
CVE-2020-19954
all versions
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary
7.5HIGH
CVE-2021-37270
all versions
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulner
9.8CRITICAL
CVE-2020-19158
all versions
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Tit
5.4MEDIUM
CVE-2020-20340
all versions
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive data
7.5HIGH
CVE-2020-19046
all versions
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page=
5.4MEDIUM
CVE-2020-20701
all versions
A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scrip
4.8MEDIUM
CVE-2020-20700
all versions
A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scr
4.8MEDIUM
CVE-2020-20699
all versions
A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a craft
4.8MEDIUM
CVE-2020-20698
all versions
A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP
7.2HIGH
CVE-2019-17368
all versions
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
6.1MEDIUM
CVE-2019-16312
all versions
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
6.1MEDIUM
CVE-2019-10708
all versions
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
9.8CRITICAL
CVE-2019-10237
all versions
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI,
8.8HIGH
CVE-2019-9925
all versions
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
6.1MEDIUM
CVE-2019-9040
all versions
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue
8.8HIGH
CVE-2019-6805
all versions
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
9.8CRITICAL
CVE-2018-20480
all versions
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.
9.8CRITICAL
CVE-2018-20479
all versions
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.
9.8CRITICAL
CVE-2018-20478
all versions
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownNam
7.5HIGH
CVE-2018-20477
all versions
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.
9.8CRITICAL
CVE-2018-20476
all versions
An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.
6.1MEDIUM
CVE-2018-20018
all versions
S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
7.5HIGH
CVE-2018-19332
all versions
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&ac
8.8HIGH
CVE-2018-19331
all versions
An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.
7.5HIGH
CVE-2018-19145
all versions
An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.
6.1MEDIUM
CVE-2018-18887
all versions
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
9.8CRITICAL
CVE-2018-18427
all versions
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
9.8CRITICAL
CVE-2018-18426
all versions
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the
8.8HIGH
CVE-2010-4772
all versions
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or
CVE-2010-4771
all versions
SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id par
CVE-2009-1502
all versions
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbit
CVE-2009-0864
all versions
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login c
CVE-2009-0863
all versions
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands
CVE-2009-0330
all versions
Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and
threatengine.sh