5none CVE Vulnerabilities & Metrics

Focus on 5none vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About 5none Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with 5none. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total 5none CVEs: 12
Earliest CVE date: 23 Jan 2018, 06:29 UTC
Latest CVE date: 08 May 2023, 14:15 UTC

Latest CVE reference: CVE-2020-18282

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical 5none CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.68

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 8
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS 5none CVEs

These are the five CVEs with the highest CVSS scores for 5none, sorted by severity first and recency.

All CVEs for 5none

CVE-2020-18282 5none vulnerability CVSS: 0 08 May 2023, 14:15 UTC

Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.

CVE-2020-18647 5none vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

CVE-2020-18646 5none vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

CVE-2020-23376 5none vulnerability CVSS: 4.3 10 May 2021, 23:15 UTC

NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.

CVE-2020-23374 5none vulnerability CVSS: 3.5 10 May 2021, 23:15 UTC

Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.

CVE-2020-23373 5none vulnerability CVSS: 3.5 10 May 2021, 23:15 UTC

Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.

CVE-2020-23371 5none vulnerability CVSS: 4.3 10 May 2021, 23:15 UTC

Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.

CVE-2019-16721 5none vulnerability CVSS: 5.8 23 Sep 2019, 14:15 UTC

NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.

CVE-2018-20062 5none vulnerability CVSS: 7.5 11 Dec 2018, 18:29 UTC

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

CVE-2018-7219 5none vulnerability CVSS: 6.8 19 Feb 2018, 14:29 UTC

application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.

CVE-2018-6029 5none vulnerability CVSS: 5.0 23 Jan 2018, 06:29 UTC

The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL validation only considers whether the URL contains the "csdn" substring.

CVE-2018-6022 5none vulnerability CVSS: 5.5 23 Jan 2018, 06:29 UTC

Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.