genix/cms
Packagist18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting genix/cmspage 1 of 1
- CVE-2015-3933CRITICALCVSS 9.8EG 9.82017-11-08
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
- CVE-2016-10096HIGHCVSS 7.3EG 7.3✓ Fixed in 1.0.02017-01-01
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
- CVE-2017-14231MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.1.02017-09-10
vulnerable: 1.0.0
GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related …
- CVE-2017-14740MEDIUMCVSS 4.82018-04-26
vulnerable: 1.1.0
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
- CVE-2017-14761MEDIUMCVSS 6.1EG 6.12017-09-27
vulnerable: 1.1.4
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.
- CVE-2017-14762MEDIUMCVSS 6.1EG 6.12017-09-27
vulnerable: 1.1.4
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.
- CVE-2017-14763HIGHCVSS 8.8EG 8.82017-09-27
vulnerable: 1.1.4
In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.
- CVE-2017-14764HIGHCVSS 8.8EG 8.82017-09-27
vulnerable: 1.1.4
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.
- CVE-2017-14765MEDIUMCVSS 6.1EG 6.12017-09-27
vulnerable: 1.1.4
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
- CVE-2017-17431MEDIUMCVSS 6.1EG 6.12017-12-05
vulnerable: 1.0.0 ... 1.1.5 (7 versions)
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
- CVE-2017-5346HIGHCVSS 7.2EG 7.2✓ Fixed in 1.0.02017-01-12
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
- CVE-2017-8376MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.1.02017-05-01
vulnerable: 1.0.0
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
- CVE-2017-8377HIGHCVSS 8.8EG 8.8✓ Fixed in 1.1.02017-05-01
vulnerable: 1.0.0
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
- CVE-2017-8388MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.1.02017-05-01
vulnerable: 1.0.0
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
- CVE-2017-8762MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.1.12017-05-03
vulnerable: 1.0.0, 1.1.0
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
- CVE-2017-8780MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.1.02017-05-04
vulnerable: 1.0.0
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.
- CVE-2017-8827CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.1.22017-05-08
vulnerable: 1.0.0, 1.1.0, 1.1.1
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.
- CVE-2022-24563MEDIUMCVSS 5.4EG 5.42022-03-03
vulnerable: 1.0.0 ... 1.1.9 (13 versions)
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.
Check whether genix/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for genix/cms CVEs against the assets you own.
Start Free Scan →