Skip to main content

Vendor/product archive

blackcat-cms / blackcat_cms CVEs

Beta · best-effort

19 CVEs tagged to blackcat-cms / blackcat_cms0 Critical, 6 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2023-53892

Published Dec 15, 2025

Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-53891

Published Dec 15, 2025

Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScrip…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44043

Published Sep 27, 2023

A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44042

Published Sep 27, 2023

A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25878

Published Jul 9, 2021

A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via cr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25877

Published Jul 9, 2021

A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via a cra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27237

Published Feb 16, 2021

The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25453

Published Sep 15, 2020

An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10821

Published Jun 14, 2018

Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTM…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5079

Published Feb 28, 2018

Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14399

Published Sep 12, 2017

In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14050

Published Aug 31, 2017

In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14049

Published Aug 31, 2017

In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14048

Published Aug 31, 2017

BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13670

Published Aug 31, 2017

In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9609

Published Jul 17, 2017

Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pag…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5521

Published Jul 14, 2015

Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.p…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5259

Published Sep 12, 2014

Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1