Nconsulting maintains a content-management system product (NC-CMS) with a modestly represented vulnerability footprint that reflects the web-application exposure inherent to publicly facing publishing platforms. The recurring weakness classes—cross-site scripting and unrestricted file uploads—are characteristic of input-handling and file-validation gaps in web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nconsulting over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18874CRITICAL nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-st | Oct 31, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-18361MEDIUM An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and conta | Oct 15, 2018 | 6.1 | 21 | NO | NO |
CVE-2019-7721HIGH lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters. | Feb 11, 2019 | 7.5 | 19 | NO | NO |
CVE-2018-18290MEDIUM An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the | Oct 14, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nconsulting.
Media articles that mention a CVE ID that affects a product developed by Nconsulting — matched by CVE ID, not by vendor name.