Skip to main content

Vendor/product archive

horizontcms_project / horizontcms CVEs

Beta · best-effort

4 CVEs tagged to horizontcms_project / horizontcms1 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-28428

Published Apr 5, 2022

File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulne…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28693

Published Nov 16, 2020

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the P…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27387

Published Nov 5, 2020

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1