HOMEVULNERABILITIESVENDORSVictor Cms Project

Victor Cms ProjectCVEs & Vulnerabilities

18 CVEs affecting Victor Cms Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

victor cms 18
CVE-2020-37076HIGH

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

4 Feb 2026
8.2
CVSS
CVE-2020-37073HIGH

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.

4 Feb 2026
8.8
CVSS
CVE-2020-37072MEDIUM

Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

4 Feb 2026
6.1
CVSS
CVE-2020-36942HIGH

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.

27 Jan 2026
8.8
CVSS
CVE-2020-23966CRITICAL

SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.

8 May 2023
9.8
CVSS
CVE-2020-35597HIGH

Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.

16 Jun 2022
8.8
CVSS
CVE-2022-28060HIGH

SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.

28 Apr 2022
7.5
CVSS
CVE-2022-27478HIGH

Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.

21 Apr 2022
8.8
CVSS
CVE-2022-26201CRITICAL

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

4 Mar 2022
9.8
CVSS
CVE-2022-23873HIGH

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.

3 Feb 2022
8.8
CVSS
CVE-2021-46459HIGH

Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.

31 Jan 2022
7.5
CVSS
CVE-2021-46458HIGH

Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.

31 Jan 2022
7.5
CVSS
CVE-2021-25203CRITICAL

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

23 Jul 2021
9.8
CVSS
CVE-2020-29280CRITICAL

The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.

3 Dec 2020
9.8
CVSS
CVE-2020-23945HIGH

A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.

27 Oct 2020
7.5
CVSS
CVE-2020-15599MEDIUMpoc

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

8 Jul 2020
6.1
CVSS
CVE-2018-16775MEDIUM

An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.

10 Sep 2018
4.8
CVSS
CVE-2018-15603MEDIUM

An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen.

21 Aug 2018
6.1
CVSS
← PrevPage 1 / 1Next →
Victor Cms Project CVEs & Vulnerabilities — 18 Tracked