Nucleus CMS is a lightweight content-management system whose vulnerability footprint centers on input-handling weaknesses in its core product, particularly cross-site scripting conditions arising from improper neutralization during web page generation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nucleus Cms over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21474CRITICAL File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2010-5041HIGH SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action | Nov 2, 2011 | 7.5 | 30 | NO | YES |
CVE-2010-5040MEDIUM PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL | Nov 2, 2011 | 6.8 | 30 | NO | YES |
CVE-2021-37770HIGH Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Ht | Jun 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2018-16636MEDIUM Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | Dec 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2008-0497MEDIUM Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted whe | Jan 30, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-5429MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter. | Oct 12, 2007 | 4.3 | 21 | NO | YES |
CVE-2006-6920MEDIUM Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN | Jan 11, 2007 | 6.8 | 18 | NO | NO |
CVE-2011-3760MEDIUM Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated b | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2008-4446MEDIUM Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Oct 6, 2008 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nucleus Cms.
Media articles that mention a CVE ID that affects a product developed by Nucleus Cms — matched by CVE ID, not by vendor name.