VendorsNjtechgreencms2.3.0603
Vulnerabilities

Njtech GreenCMS 2.3.0603

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2018-11670
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.
Published 2018-06-01 · Modified
8.81 PoCEPSS 0.025
CVE-2018-11671
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.
Published 2018-06-01 · Modified
8.81 PoCEPSS 0.025
CVE-2022-28918
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.
Published 2022-04-26 · Modified
8.1EPSS 0.011
CVE-2018-12604
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
Published 2018-06-20 · Modified
7.51 PoCEPSS 0.132
CVE-2025-14244
GreenCMS Menu Management CustomController.class.php cross site scripting
Published 2025-12-08 · Analyzed
4.8EPSS 0.003