Luocms

Vendor:

First CVE: Mar 10, 2022 · Active for 4 years

10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
9.2
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Luocms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2022
4 years ago
Most Recent CVE
Mar 10, 2022
1,599 days ago

CVE Severity & Scoring

Luocms10 CVEs
All CVEs352,713 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
Mar 10, 20229.831NONO
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
Mar 10, 20229.831NONO
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
Mar 10, 20229.830NONO
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
Mar 10, 20229.829NONO
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
Mar 10, 20229.829NONO
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
Mar 10, 20229.829NONO
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
Mar 10, 20229.829NONO
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
Mar 10, 20229.829NONO
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.
Mar 10, 20227.524NONO
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
Mar 10, 20226.120NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Luocms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0109.21.1%00