
CVE-2025-0346 – code-projects Content Management System Publish News Page publishnews.php unrestricted upload
https://notcve.org/view.php?id=CVE-2025-0346
09 Jan 2025 — A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. • https://code-projects.org • CWE-284: Improper Access Control CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2024-10758 – code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
https://notcve.org/view.php?id=CVE-2024-10758
04 Nov 2024 — A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://packetstorm.news/files/id/190437 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-48985
https://notcve.org/view.php?id=CVE-2023-48985
14 Feb 2024 — Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component. Vulnerabilidad de Cross-Site Scripting (XSS) en CU Solutions Group (CUSG) Content Management System (CMS) anterior a v.7.75 permite a un atacante remoto ejecutar código arbitrario, escalar privilegios y obtener información confidencial a tra... • https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-48986
https://notcve.org/view.php?id=CVE-2023-48986
14 Feb 2024 — Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component. Vulnerabilidad de Cross-Site Scripting (XSS) en CU Solutions Group (CUSG) Content Management System (CMS) anterior a v.7.75 permite a un atacante remoto ejecutar código arbitrario, escalar privilegios y obtener información confidencial a tra... • https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-48987
https://notcve.org/view.php?id=CVE-2023-48987
14 Feb 2024 — Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component. Vulnerabilidad de inyección SQL ciega en CU Solutions Group (CUSG) Content Management System (CMS) anterior a v.7.75 permite a un atacante remoto ejecutar código arbitrario, escalar privilegios y obtener información confidencial a través de un scri... • https://www.lmgsecurity.com/news/critical-software-vulnerabilities-impacting-credit-unions-discovered-by-lmg-security-researcher-immediate-action-recommended • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-31816
https://notcve.org/view.php?id=CVE-2023-31816
22 May 2023 — IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php. • https://github.com/TzssZ/Content-Management-System-v1.0-has-Cross-site-Scripting-XSS- • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-26565
https://notcve.org/view.php?id=CVE-2022-26565
01 Apr 2022 — A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. Una vulnerabilidad de cross-site scripting (XSS) en Totaljs todas las versiones antes del commit 95f54a5commit, permite a los atacantes ejecutar scripts web o HTML arbitrarios a través de un payload crafteado inyectado en el campo de texto Page Name al crear una nueva pá... • https://bug.pocas.kr/2022/03/01/2022-03-05-CVE-2022-26565 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-25197
https://notcve.org/view.php?id=CVE-2021-25197
22 Jul 2021 — Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php Una vulnerabilidad de tipo Cross-site scripting (XSS) en SourceCodester Content Management System versión v1.0, permite a atacantes remotos inyectar script web o HTML arbitrario por medio del parámetro search en el archivo content_management_system\admin\new_content.php • https://github.com/TCSWT/Content-Management-System/blob/main/README.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2007-4365
https://notcve.org/view.php?id=CVE-2007-4365
15 Aug 2007 — Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en eXV2 CMS 2.0.5 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante una cookie set_lang para un componente no especificado. NOTA: esto podría solaparse con CVE-2007-... • http://osvdb.org/36479 •

CVE-2007-1965
https://notcve.org/view.php?id=CVE-2007-1965
11 Apr 2007 — Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en eXV2 CMS 2.0.4.3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a (1) archive.php, (2) article.php, (3) index.php, o (4) topics.php. • http://marc.info/?l=bugtraq&m=117570977117962&w=2 •