Ed01 Cms
Vendor:
First CVE: Nov 3, 2021 · Active for 4 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ed01 Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2021
4 years ago
Most Recent CVE
Apr 25, 2024
822 days ago
CVE Severity & Scoring
Ed01 Cms6 CVEs
33%
17%
50%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28524CRITICAL ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | Apr 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-18262CRITICAL ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | Nov 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-18261CRITICAL An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. | Nov 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-28525HIGH ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | Apr 26, 2022 | 8.8 | 22 | NO | NO |
CVE-2020-18259MEDIUM ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary | Nov 3, 2021 | 6.1 | 20 | NO | NO |
CVE-2024-30890MEDIUM Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. | Apr 25, 2024 | 4.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Ed01 Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 20180505 | 2 | 9.3 | 0.9% | 0 | 0 |
| 1.0 | 4 | 7.6 | 0.8% | 0 | 0 |