Espcms P8
Vendor:
First CVE: Aug 24, 2021 · Active for 4 years
2
Total CVEs
More Total CVEs than 49% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Espcms P8 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2021
4 years ago
Most Recent CVE
Jun 30, 2022
1,485 days ago
CVE Severity & Scoring
Espcms P82 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (50.0%)
None1 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-18913HIGH EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers | Aug 24, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-33085HIGH ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates. | Jun 30, 2022 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Espcms P8
Top CWEs
Versions
No cataloged versions.