Vendorstp5cms Projecttp5cmsany version
Vulnerabilities

tp5cms Project tp5cms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2018-19692
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
Published 2018-11-29 · Modified
9.8EPSS 0.015
CVE-2018-15568
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
Published 2018-08-20 · Modified
8.8EPSS 0.005
CVE-2018-19693
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
Published 2018-11-29 · Modified
6.1EPSS 0.007
CVE-2018-15566
tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
Published 2018-08-20 · Modified
6.1EPSS 0.007
CVE-2021-31280
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
Published 2023-06-14 · Modified
6.1EPSS 0.004