MidnightBSD

Advisories for nucleuscms

CVE-2011-3760 MEDIUM

Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/api_nucleus.inc.php and certain other files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
nucleuscms nucleus_cms 3.61
CVE-2015-5454 MEDIUM

Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
nucleuscms nucleus_cms 3.65
nucleuscms nucleus_cms 3.70
CVE-2018-16636 MEDIUM

Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
nucleuscms nucleus_cms 3.70