VendorsEcispespcms-p8all versions
Vulnerabilities

Ecisp EARCLINK ESPCMS-P8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-18913
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
Published 2021-08-24 · Modified
7.5EPSS 0.013
CVE-2022-33085
ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.
Published 2022-06-30 · Modified
7.2EPSS 0.019