Filtered by vendor Hkcms Subscriptions
Filtered by product Hkcms Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-52677 1 Hkcms 1 Hkcms 2024-11-26 9.8 Critical
HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.
CVE-2023-40786 1 Hkcms 1 Hkcms 2024-11-21 5.4 Medium
HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.