📦 Frogcms

by Frogcms Project

🔍 What is Frogcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-26794

CRITICAL CVSS 9.8 Sep 23, 2021

This vulnerability allows attackers to upload malicious PHP files through the upload.php script in FrogCMS SentCMS, leading to remote code execution and privilege escalation. Any organization running ...

CVE-2024-46086

HIGH CVSS 8.8 Sep 18, 2024

This CSRF vulnerability in FrogCMS allows attackers to trick authenticated administrators into performing unauthorized file deletion actions. Attackers can craft malicious requests that delete files w...

CVE-2024-46085

HIGH CVSS 8.8 Sep 17, 2024

FrogCMS V0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the file manager rename functionality. This allows attackers to trick authenticated administrators into performing unauthor...

CVE-2024-42625

HIGH CVSS 8.8 Aug 12, 2024

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout addition functionality at /admin/?/layout/add. This allows attackers to trick authenticated administrators into ...

CVE-2024-42627

HIGH CVSS 8.8 Aug 12, 2024

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the snippet deletion functionality. Attackers can trick authenticated administrators into unknowingly deleting snippets via...

CVE-2024-42623

HIGH CVSS 8.8 Aug 12, 2024

FrogCMS v0.9.5 contains a CSRF vulnerability in the layout deletion endpoint that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all FrogCMS ...

CVE-2024-42631

HIGH CVSS 8.8 Aug 12, 2024

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout editing functionality at /admin/?/layout/edit/1. This allows attackers to trick authenticated administrators int...

CVE-2024-42629

HIGH CVSS 8.8 Aug 12, 2024

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the page edit functionality at /admin/?/page/edit/10. This allows attackers to trick authenticated administrators into perf...