VendorsBlackCat CMSblackcat_cmsany version
Vulnerabilities

BlackCat CMS Blackcat CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-25453
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Published 2020-09-15 · Modified
8.81 PoCEPSS 0.063
CVE-2015-5079
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.
Published 2018-02-28 · Modified
7.51 PoCEPSS 0.170
CVE-2014-5259
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Published 2014-09-12 · Modified
4.3EPSS 0.020