Skip to main content

Vendor/product archive

siberiancms / siberiancms CVEs

Beta · best-effort

7 CVEs tagged to siberiancms / siberiancms1 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-1105

Published Feb 7, 2025

A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-41702

Published Jul 30, 2024

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39378

Published Sep 27, 2023

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39377

Published Sep 27, 2023

SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecif…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39376

Published Sep 27, 2023

SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6906

Published Mar 15, 2017

An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1