📦 Cuppacms

by Cuppacms

🔍 What is Cuppacms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-47990

CRITICAL CVSS 9.8 Dec 20, 2023

This CVE describes a SQL injection vulnerability in CuppaCMS V1.0, specifically in the edit_admin_table.php component. Attackers can execute arbitrary SQL commands via the 'table' parameter, potential...

CVE-2023-39681

CRITICAL CVSS 9.8 Sep 5, 2023

Cuppa CMS v1.0 contains a critical remote code execution vulnerability in the email_outgoing parameter at /Configuration.php. Attackers can execute arbitrary code on affected systems by sending a craf...

CVE-2022-27984

CRITICAL CVSS 9.8 Apr 26, 2022

CVE-2022-27984 is a critical SQL injection vulnerability in CuppaCMS v1.0 that allows attackers to execute arbitrary SQL commands via the menu_filter parameter. This affects all installations of Cuppa...

CVE-2022-25498

CRITICAL CVSS 9.8 Mar 15, 2022

CVE-2022-25498 is a critical remote code execution vulnerability in CuppaCMS v1.0 that allows attackers to execute arbitrary code on affected systems via the saveConfigData function. This affects all ...

CVE-2022-34121

HIGH CVSS 7.5 Jul 27, 2022

CVE-2022-34121 is a local file inclusion vulnerability in Cuppa CMS v1.0 that allows attackers to read arbitrary files on the server via the /templates/default/html/windows/right.php component. This a...

CVE-2022-25485

HIGH CVSS 7.8 Mar 15, 2022

CVE-2022-25485 is a local file inclusion vulnerability in CuppaCMS v1.0 that allows attackers to read arbitrary files on the server via the url parameter in /alerts/alertLightbox.php. This affects all...

CVE-2022-25401

HIGH CVSS 7.5 Feb 24, 2022

This vulnerability in Cuppa CMS v1.0 allows attackers to copy arbitrary files to the current directory via the file manager's copy function, enabling unauthorized read access to sensitive files. Any s...

CVE-2022-24265

HIGH CVSS 7.5 Jan 31, 2022

CVE-2022-24265 is a SQL injection vulnerability in Cuppa CMS v1.0 that allows attackers to execute arbitrary SQL commands via the menu_filter parameter. This affects all installations of Cuppa CMS v1....

CVE-2021-3376

HIGH CVSS 8.8 Dec 14, 2021

CVE-2021-3376 is a privilege escalation vulnerability in Cuppa CMS that allows authenticated attackers to elevate their privileges via a crafted POST request. This affects all Cuppa CMS installations ...