ClippercmsCVEs & Vulnerabilities

10 CVEs affecting Clippercms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

clippercms 10
CVE-2022-41497CRITICAL

ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

14 Oct 2022
9.8
CVSS
CVE-2022-41495CRITICAL

ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

14 Oct 2022
9.8
CVSS
CVE-2018-12101MEDIUM

CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.

15 Aug 2019
5.4
CVSS
CVE-2018-19424HIGH

ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

21 Nov 2018
7.2
CVSS
CVE-2018-19135HIGHpoc

ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.

11 Nov 2018
8.8
CVSS
CVE-2018-13998MEDIUM

ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.

12 Jul 2018
4.8
CVSS
CVE-2018-13106MEDIUM

ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.

3 Jul 2018
4.8
CVSS
CVE-2018-11572MEDIUM

ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.

31 May 2018
5.4
CVSS
CVE-2018-11571HIGH

ClipperCMS 1.3.3 allows Session Fixation.

31 May 2018
8.8
CVSS
CVE-2018-11332MEDIUMpoc

Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.

24 May 2018
4.8
CVSS
← PrevPage 1 / 1Next →
Clippercms CVEs & Vulnerabilities — 10 Tracked