VendorsAnchor CMSanchor_cmsany version
Vulnerabilities

Anchor CMS Anchor CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-44116
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
Published 2021-12-15 · Modified
6.1EPSS 0.007
CVE-2015-5060
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
Published 2017-09-07 · Modified
6.1EPSS 0.007
CVE-2014-9182
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
Published 2014-12-02 · Modified
4.3EPSS 0.010