Lokicms is a content-management system with a vulnerability profile centered on its core product, characterized by recurring input-handling weaknesses including path-traversal flaws and code-injection issues that are typical of web application platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lokicms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1860HIGH Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default paramete | Apr 17, 2008 | 9.3 | 35 | NO | YES |
CVE-2008-4662MEDIUM Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (d | Oct 22, 2008 | 6.8 | 27 | NO | YES |
CVE-2008-5965MEDIUM Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary file | Jan 26, 2009 | 5.0 | 24 | NO | YES |
CVE-2008-6643MEDIUM LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify | Apr 7, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-4913MEDIUM Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter. | Nov 4, 2008 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lokicms.
Media articles that mention a CVE ID that affects a product developed by Lokicms — matched by CVE ID, not by vendor name.