Torrahclef Company Website Cms vulnerabilities
5 known vulnerabilities affecting torrahclef/company_website_cms.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-13560MEDIUMCVSS 6.9v1.02025-11-23
CVE-2025-13560 [MEDIUM] CWE-74 CVE-2025-13560: A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
nvd
CVE-2025-13561MEDIUMCVSS 6.9v1.02025-11-23
CVE-2025-13561 [MEDIUM] CWE-74 CVE-2025-13561: A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2025-29708CRITICALCVSS 9.8v1.02025-04-16
CVE-2025-29708 [CRITICAL] CWE-73 CVE-2025-29708: SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services
SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
nvd
CVE-2025-29709CRITICALCVSS 9.8v1.02025-04-16
CVE-2025-29709 [CRITICAL] CWE-73 CVE-2025-29709: SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" fi
SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.
nvd
CVE-2025-29710MEDIUMCVSS 6.1v1.02025-04-16
CVE-2025-29710 [MEDIUM] CWE-79 CVE-2025-29710: SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Se
SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
nvd