ExponentcmsCVEs & Vulnerabilities

60 CVEs affecting Exponentcms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

exponent cms 110exponentcms 1
CVE-2021-32441HIGH

SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.

17 Feb 2023
7.5
CVSS
CVE-2022-23049MEDIUM

Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.

10 Feb 2022
5.4
CVSS
CVE-2022-23048HIGH

Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.

10 Feb 2022
7.2
CVSS
CVE-2022-23047MEDIUM

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

10 Feb 2022
4.8
CVSS
CVE-2021-38751MEDIUM

A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.

16 Aug 2021
4.3
CVSS
CVE-2016-9026CRITICAL

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

31 Dec 2020
9.8
CVSS
CVE-2016-9025CRITICAL

Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

31 Dec 2020
9.8
CVSS
CVE-2016-9023CRITICAL

Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

31 Dec 2020
9.8
CVSS
CVE-2016-9022CRITICAL

Exponent CMS before 2.6.0 has improper input validation in usersController.php.

31 Dec 2020
9.8
CVSS
CVE-2016-9021CRITICAL

Exponent CMS before 2.6.0 has improper input validation in storeController.php.

31 Dec 2020
9.8
CVSS
CVE-2016-8900CRITICAL

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.

24 May 2019
9.8
CVSS
CVE-2016-8898CRITICAL

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.

24 May 2019
9.8
CVSS
CVE-2016-8899CRITICAL

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.

23 May 2019
9.8
CVSS
CVE-2016-8897CRITICAL

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.

23 May 2019
9.8
CVSS
CVE-2016-7443CRITICAL

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

7 Mar 2018
9.8
CVSS
CVE-2017-18213HIGH

In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.

4 Mar 2018
7.2
CVSS
CVE-2015-1177MEDIUM

Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.

28 Aug 2017
6.1
CVSS
CVE-2017-8085MEDIUM

In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.

24 Apr 2017
6.1
CVSS
CVE-2017-7991CRITICAL

Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.

22 Apr 2017
9.8
CVSS
CVE-2016-9087CRITICAL

SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-9020CRITICAL

SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-9019CRITICAL

SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7789CRITICAL

SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7788CRITICAL

SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7784CRITICAL

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7783CRITICAL

SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7782CRITICAL

SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7781CRITICAL

SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7780CRITICAL

SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

7 Mar 2017
9.8
CVSS
CVE-2016-7565CRITICAL

install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.

13 Feb 2017
9.8
CVSS
CVE-2016-7400CRITICALpoc

Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.

7 Feb 2017
9.8
CVSS
CVE-2017-5879CRITICAL

An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src.

6 Feb 2017
9.8
CVSS
CVE-2016-2242CRITICAL

Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

23 Jan 2017
9.8
CVSS
CVE-2015-8684MEDIUM

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

18 Jan 2017
6.1
CVSS
CVE-2015-8667MEDIUM

Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the Username/Email.

18 Jan 2017
6.1
CVSS
CVE-2016-7791CRITICAL

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which leads to arbitrary code execution.

13 Jan 2017
9.8
CVSS
CVE-2016-7790CRITICAL

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.

13 Jan 2017
9.8
CVSS
CVE-2016-9481CRITICAL

In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' used directly in SQL. Impact is a SQL injection.

30 Nov 2016
9.8
CVSS
CVE-2016-9287CRITICAL

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

15 Nov 2016
9.8
CVSS
CVE-2016-9288CRITICAL

In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1.

12 Nov 2016
9.8
CVSS
CVE-2016-9286MEDIUM

framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI.

12 Nov 2016
5.3
CVSS
CVE-2016-9285MEDIUM

framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue.

12 Nov 2016
5.3
CVSS
CVE-2016-9284MEDIUM

getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.

12 Nov 2016
5.3
CVSS
CVE-2016-9283HIGH

SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related to a "sef URL" issue.

12 Nov 2016
7.5
CVSS
CVE-2016-9282HIGH

SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_string parameter.

12 Nov 2016
7.5
CVSS
CVE-2016-9272CRITICAL

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

11 Nov 2016
9.1
CVSS
CVE-2016-9242HIGH

Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter.

7 Nov 2016
8.8
CVSS
CVE-2016-9184HIGH

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

4 Nov 2016
7.5
CVSS
← PrevPage 1 / 2Next →