Skip to main content

Vendor/product archive

classcms / classcms CVEs

Beta · best-effort

8 CVEs tagged to classcms / classcms2 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-57099

Published Feb 3, 2025

ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, al…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57097

Published Feb 3, 2025

ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12666

Published Dec 16, 2024

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12503

Published Dec 12, 2024

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48180

Published Oct 16, 2024

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8145

Published Aug 25, 2024

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the comp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8144

Published Aug 25, 2024

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25581

Published Mar 18, 2022

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt fi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1