CVE Tools

Lovecms

7 CVEs tracked since 2007. Since Feb 2007, none of them reached CISA KEV.

Lovecms CVEs per month

Feb 2007 to Dec 2008. Point at a month, or focus the strip and use the arrow keys.
Lovecms CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2007-0240
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-0810
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-1220

Products

The products that kept showing up in Lovecms's monthly top three, with their CVEs summed over those months.

  1. Lovecms63 months
  2. The Simple Forum11 month

Latest CVEs

The 8 most recently published vulnerabilities affecting Lovecms.

  1. CVE-2008-7062Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute arbitrary code by uploading a file with an execut...6.8
  2. CVE-2008-5794Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.5.0
  3. CVE-2008-5308The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct re...7.5
  4. CVE-2008-3509LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or ...7.5
  5. CVE-2007-1149Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load paramete...5.0
  6. CVE-2007-1151Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.4.3
  7. CVE-2007-1150Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.3.6
  8. CVE-2007-1148PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.7.5

The record

Peak rank
#21 in Feb 2007
Busiest month shown
Feb 2007, 4 CVEs
Months with a KEV entry
0 since Feb 2007
Monthly snapshots
3 since 2007
Lovecms's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store