Skip to main content

Vendor/product archive

weaselcms_project / weaselcms CVEs

Beta · best-effort

5 CVEs tagged to weaselcms_project / weaselcms1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2018-17361

Published Sep 23, 2018

Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is misha…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16352

Published Sep 2, 2018

There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14958

Published Aug 5, 2018

An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14877

Published Aug 3, 2018

An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1