361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
802
This Week
36 results · Page 1/2
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.
metalgenix
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
metalgenix
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
metalgenix
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
genixcms