shishuocms(师说CMS)是gaofeng4623个人开发者的一个学习内容管理系统。 shishuocms 1.1版本存在代码问题漏洞,该漏洞源于ManageUpLoadAction.java文件存在无限制上传,可能导致远程攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | shishuocms | 1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-1843 | 6.3 MEDIUM | Mini-Tmall ProductMapper.java select sql injection |
| CVE-2025-1891 | 4.3 MEDIUM | shishuocms cross-site request forgery |
| CVE-2024-55064 | EasyVirt DC NetScope 跨站脚本漏洞 | |
| CVE-2025-25939 | Reprise Software Reprise License Manager 跨站脚本漏洞 | |
| CVE-2025-25967 | DDSN Interactive Acora CMS 跨站请求伪造漏洞 | |
| CVE-2025-26206 | storefront 跨站请求伪造漏洞 | |
| CVE-2024-51091 | Sea.js 跨站脚本漏洞 | |
| CVE-2023-49031 | Tikit 安全漏洞 | |
| CVE-2024-53384 | tsup 跨站脚本漏洞 | |
| CVE-2024-53388 | Mavo 跨站脚本漏洞 | |
| CVE-2024-53387 | UMeditor 跨站脚本漏洞 | |
| CVE-2024-57240 | Apryse WebViewer 跨站脚本漏洞 | |
| CVE-2024-55570 | Cubro EXA48200 安全漏洞 | |
| CVE-2025-25948 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25953 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25950 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25952 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-25949 | Serosoft Solutions Academia Student Information System EagleR 跨站脚本漏洞 | |
| CVE-2025-25951 | Serosoft Solutions Academia Student Information System EagleR 安全漏洞 | |
| CVE-2025-27584 | Serosoft Solutions Academia Student Information System EagleR 跨站脚本漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet