Kkcms ProjectCVEs & Vulnerabilities
3 CVEs affecting Kkcms Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
kkcms 3
CVE-2022-32101CRITICAL
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
15 Jun 2022
9.8
CVSS
CVE-2019-16923MEDIUM
kkcms 1.3 has jx.php?url= XSS.
27 Sep 2019
6.1
CVSS
CVE-2019-16706HIGH
kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
23 Sep 2019
8.8
CVSS
← PrevPage 1 / 1Next →