Vulnerabilities (CVE)

Filtered by vendor Frogcms Project Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46086 1 Frogcms Project 1 Frogcms 2024-09-25 N/A 8.8 HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
CVE-2024-46394 1 Frogcms Project 1 Frogcms 2024-09-25 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
CVE-2024-42628 1 Frogcms Project 1 Frogcms 2024-08-15 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.
CVE-2024-42624 1 Frogcms Project 1 Frogcms 2024-08-15 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.
CVE-2024-42623 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1
CVE-2024-42631 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.
CVE-2024-42627 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.
CVE-2024-42625 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add
CVE-2024-42629 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
CVE-2024-42632 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.
CVE-2024-42630 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.
CVE-2024-42626 1 Frogcms Project 1 Frogcms 2024-08-13 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.
CVE-2020-25872 1 Frogcms Project 1 Frogcms 2024-02-04 4.0 MEDIUM 4.9 MEDIUM
A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.
CVE-2021-26794 1 Frogcms Project 1 Frogcms 2024-02-04 7.5 HIGH 9.8 CRITICAL
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
CVE-2018-16447 1 Frogcms Project 1 Frogcms 2024-02-04 6.8 MEDIUM 8.8 HIGH
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
CVE-2018-19844 1 Frogcms Project 1 Frogcms 2024-02-04 3.5 LOW 4.8 MEDIUM
FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319.
CVE-2018-10319 1 Frogcms Project 1 Frogcms 2024-02-04 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
CVE-2018-10806 1 Frogcms Project 1 Frogcms 2024-02-04 3.5 LOW 5.4 MEDIUM
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.
CVE-2018-10570 1 Frogcms Project 1 Frogcms 2024-02-04 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
CVE-2018-10321 1 Frogcms Project 1 Frogcms 2024-02-04 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.