VendorsThecosyicecms1.0.0
Vulnerabilities

Thecosy Icecms 1.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-40833
An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.
Published 2023-10-12 · Modified
9.8EPSS 0.007
CVE-2023-33355
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.
Published 2023-05-25 · Modified
7.5EPSS 0.006
CVE-2023-33356
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
Published 2023-05-25 · Modified
5.4EPSS 0.004