Victor Cms Project Victor Cms vulnerabilities
18 known vulnerabilities affecting victor_cms_project/victor_cms.
Total CVEs
18
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH10MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2022-27478P2HIGHCVSS 8.8v1.02022-04-21
CVE-2022-27478 [HIGH] CWE-434 CVE-2022-27478: Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.
nvd
CVE-2021-25203P3CRITICALCVSS 9.8v1.02021-07-23
CVE-2021-25203 [CRITICAL] CWE-434 CVE-2021-25203: Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code v
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
nvd
CVE-2020-15599P3MEDIUMCVSS 6.1PoC≤ 2019-02-282020-07-07
CVE-2020-15599 [MEDIUM] CWE-79 CVE-2020-15599: Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
nvd
CVE-2020-36942P3HIGHCVSS 8.8v1.02026-01-27
CVE-2020-36942 [HIGH] CWE-434 CVE-2020-36942: Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malici
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.
nvd
CVE-2020-37073P3HIGHCVSS 8.8v1.02026-02-03
CVE-2020-37073 [HIGH] CWE-434 CVE-2020-37073: Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upl
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.
nvd
CVE-2020-37076P3HIGHCVSS 8.2v1.02026-02-03
CVE-2020-37076 [HIGH] CWE-89 CVE-2020-37076: Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php th
Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.
nvd
CVE-2020-23966P3CRITICALCVSS 9.8v1.02023-05-08
CVE-2020-23966 [CRITICAL] CWE-89 CVE-2020-23966: SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
nvd
CVE-2020-35597P3HIGHCVSS 8.8v1.02022-06-16
CVE-2020-35597 [HIGH] CWE-89 CVE-2020-35597: Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id par
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
nvd
CVE-2022-23873P3HIGHCVSS 8.8v1.02022-02-03
CVE-2022-23873 [HIGH] CWE-89 CVE-2022-23873: Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inj
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
nvd
CVE-2022-26201P3CRITICALCVSS 9.8v1.02022-03-04
CVE-2022-26201 [CRITICAL] CWE-89 CVE-2022-26201: Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
nvd
CVE-2020-29280P3CRITICALCVSS 9.8v1.02020-12-02
CVE-2020-29280 [CRITICAL] CWE-89 CVE-2020-29280: The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the sea
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
nvd
CVE-2022-28060P3HIGHCVSS 7.5v1.02022-04-28
CVE-2022-28060 [HIGH] CWE-89 CVE-2022-28060: SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
nvd
CVE-2021-46458P3HIGHCVSS 7.5v1.02022-01-31
CVE-2021-46458 [HIGH] CWE-89 CVE-2021-46458: Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.
nvd
CVE-2021-46459P3HIGHCVSS 7.5v1.02022-01-31
CVE-2021-46459 [HIGH] CWE-89 CVE-2021-46459: Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component ad
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.
nvd
CVE-2020-23945P3HIGHCVSS 7.5v1.02020-10-27
CVE-2020-23945 [HIGH] CWE-89 CVE-2020-23945: A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
nvd
CVE-2020-37072P4MEDIUMCVSS 6.1v1.02026-02-03
CVE-2020-37072 [MEDIUM] CWE-79 CVE-2020-37072: Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST par
Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.
nvd
CVE-2018-15603P4MEDIUMCVSS 6.1≤ 2018-05-102018-08-21
CVE-2018-15603 [MEDIUM] CWE-79 CVE-2018-15603: An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen.
nvd
CVE-2018-16775P4MEDIUMCVSS 4.8≤ 2018-05-102018-09-10
CVE-2018-16775 [MEDIUM] CWE-79 CVE-2018-16775: An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Cat
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
nvd