Skip to main content

Vendor archive

snewscms CVEs

Beta · best-effort

4 CVEs tagged to vendor snewscms1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2016-20052

Published Apr 4, 2026

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files direc…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-20051

Published Apr 4, 2026

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2011-2706

Published Jan 14, 2020

A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5303

Published Oct 9, 2007

Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1