Vendorstpcms projecttpcmsall versions
Vulnerabilities

tpcms project tpcms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-29624
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-05-31 · Modified
8.8EPSS 0.013
CVE-2022-27442
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
Published 2022-04-04 · Modified
7.5EPSS 0.010
CVE-2021-36544
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
Published 2023-02-03 · Modified
7.5EPSS 0.009
CVE-2021-36545
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page.
Published 2023-02-03 · Modified
5.4EPSS 0.005
CVE-2022-27441
A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box.
Published 2022-04-04 · Modified
4.8EPSS 0.004