📦 Taocms

by Taogogo

🔍 What is Taocms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33350

CRITICAL CVSS 9.8 Apr 29, 2024

A directory traversal vulnerability in TaoCMS v3.0.2 allows remote attackers to write arbitrary files via the include/model/file.php component. This can lead to remote code execution and sensitive inf...

CVE-2022-23880

CRITICAL CVSS 9.8 Mar 23, 2022

This vulnerability allows attackers to upload malicious PHP files through taoCMS's File Management module, leading to remote code execution. It affects all taoCMS v3.0.2 installations with the vulnera...

CVE-2022-25505

CRITICAL CVSS 9.8 Mar 21, 2022

CVE-2022-25505 is a critical SQL injection vulnerability in Taocms v3.0.2 that allows attackers to execute arbitrary SQL commands via the id parameter in Category.php. This affects all users running t...

CVE-2021-46204

CRITICAL CVSS 9.8 Jan 19, 2022

Taocms v3.0.2 contains both an arbitrary file read vulnerability via the path parameter and an SQL injection vulnerability in Article.php. This allows attackers to read sensitive files from the server...

CVE-2021-45015

CRITICAL CVSS 9.1 Dec 14, 2021

CVE-2021-45015 is an arbitrary file deletion vulnerability in TaoCMS that allows attackers to delete any file on the server. This affects TaoCMS 3.0.2 installations where attackers can exploit insuffi...

CVE-2021-34167

HIGH CVSS 8.8 Feb 24, 2023

This CSRF vulnerability in taoCMS 3.0.2 allows attackers to trick authenticated administrators into performing unintended actions, potentially granting attackers escalated privileges. It affects all t...

CVE-2021-25784

HIGH CVSS 7.2 Dec 2, 2021

CVE-2021-25784 is a blind SQL injection vulnerability in Taocms v2.5Beta5 that allows attackers to execute arbitrary SQL commands through the Edit Article function. This affects all users running the ...