5none maintains a modestly represented product line centered on NoneCMS, a web content management system, where vulnerabilities cluster around web-application input handling and access-control boundaries. The exposure recurs through weakness classes including cross-site scripting, cross-site request forgery, path traversal, and exposure to unintended resource spheres—typical of CMS platforms where user-supplied content and administrative boundaries intersect. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 5none over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20062CRITICAL An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrat | Dec 11, 2018 | 9.8 | 99 | YES | YES |
CVE-2018-7219HIGH application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html re | Feb 19, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-18647HIGH Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor". | Jun 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-6029HIGH The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server S | Jan 23, 2018 | 7.5 | 23 | NO | NO |
CVE-2020-18282MEDIUM Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2020-23376MEDIUM NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML | May 10, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-16721MEDIUM NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. | Sep 23, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-6022MEDIUM Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-o | Jan 23, 2018 | 6.5 | 21 | NO | NO |
CVE-2020-23371MEDIUM Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web scr | May 10, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-18646HIGH Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php". | Jun 22, 2021 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 5none.
Media articles that mention a CVE ID that affects a product developed by 5none — matched by CVE ID, not by vendor name.