Nonecms
Vendor:
First CVE: Jan 23, 2018 · Active for 8 years
12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Nonecms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2018
8 years ago
Most Recent CVE
May 8, 2023
1,173 days ago
CVE Severity & Scoring
Nonecms12 CVEs
58%
33%
8%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (41.7%)
Unknown0 (0.0%)
Required7 (58.3%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None9 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20062CRITICAL An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrat | Dec 11, 2018 | 9.8 | 99 | YES | YES |
CVE-2018-7219HIGH application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html re | Feb 19, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-18647HIGH Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor". | Jun 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-6029HIGH The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server S | Jan 23, 2018 | 7.5 | 23 | NO | NO |
CVE-2020-18282MEDIUM Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2020-23376MEDIUM NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML | May 10, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-16721MEDIUM NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. | Sep 23, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-6022MEDIUM Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-o | Jan 23, 2018 | 6.5 | 21 | NO | NO |
CVE-2020-23371MEDIUM Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web scr | May 10, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-18646HIGH Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php". | Jun 22, 2021 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
1 CVE
8.3% of CVEs· 97th percentile
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
1 CVE
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Nonecms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.0 | 11 | 7.0 | 9.8% | 1 | 1 |