Hongcms ProjectCVEs & Vulnerabilities

20 CVEs affecting Hongcms Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

hongcms 20
CVE-2020-21252HIGH

Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.

20 Jun 2023
8.8
CVSS
CVE-2020-21643MEDIUM

Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.

28 Apr 2023
6.1
CVSS
CVE-2022-32412HIGH

An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

2 Jul 2022
7.2
CVSS
CVE-2022-32411HIGH

An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.

2 Jul 2022
7.2
CVSS
CVE-2022-28523HIGH

HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

27 Apr 2022
8.1
CVSS
CVE-2020-21431MEDIUM

HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.

5 Oct 2021
6.5
CVSS
CVE-2020-18178CRITICAL

Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."

18 May 2021
9.8
CVSS
CVE-2019-17611MEDIUM

HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.

17 Oct 2019
6.1
CVSS
CVE-2019-17610MEDIUM

HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.

17 Oct 2019
6.1
CVSS
CVE-2019-17609MEDIUM

HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.

17 Oct 2019
6.1
CVSS
CVE-2019-17608MEDIUM

HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.

17 Oct 2019
6.1
CVSS
CVE-2019-17607MEDIUM

HongCMS 3.0.0 has XSS via the install/index.php servername parameter.

17 Oct 2019
6.1
CVSS
CVE-2019-16867MEDIUM

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)

25 Sep 2019
6.5
CVSS
CVE-2019-8407MEDIUM

HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.

17 Feb 2019
6.5
CVSS
CVE-2018-16774HIGH

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

10 Sep 2018
7.5
CVSS
CVE-2018-13021HIGH

An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.

29 Jun 2018
7.2
CVSS
CVE-2018-12912HIGHpoc

An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

27 Jun 2018
7.2
CVSS
CVE-2018-12266MEDIUM

system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.

13 Jun 2018
6.1
CVSS
CVE-2018-10422MEDIUM

An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field.

26 Apr 2018
4.8
CVSS
CVE-2018-10265HIGH

An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.

22 Apr 2018
8.8
CVSS
← PrevPage 1 / 1Next →
Hongcms Project CVEs & Vulnerabilities — 20 Tracked