Vulnerabilities (CVE)

Filtered by vendor Aquila-cms Subscribe
Filtered by product Aquilacms
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48572 1 Aquila-cms 1 Aquilacms 2025-04-22 N/A 5.3 MEDIUM
A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed as a regular expression, which is then matched against email addresses to find duplicate entries.
CVE-2024-48573 1 Aquila-cms 1 Aquilacms 2025-04-22 N/A 9.8 CRITICAL
A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.