Vulnerabilities (CVE)

Filtered by vendor Tpcms Project Subscribe
Filtered by product Tpcms
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27442 1 Tpcms Project 1 Tpcms 2024-11-21 5.0 MEDIUM 7.5 HIGH
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
CVE-2022-27441 1 Tpcms Project 1 Tpcms 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box.