
CVE-2025-0346 – code-projects Content Management System Publish News Page publishnews.php unrestricted upload
https://notcve.org/view.php?id=CVE-2025-0346
09 Jan 2025 — A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. • https://code-projects.org • CWE-284: Improper Access Control CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2024-10758 – code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
https://notcve.org/view.php?id=CVE-2024-10758
04 Nov 2024 — A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://packetstorm.news/files/id/190437 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •