frog_cms_project CVE Vulnerabilities & Metrics

Focus on frog_cms_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About frog_cms_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with frog_cms_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total frog_cms_project CVEs: 18
Earliest CVE date: 22 Mar 2018, 04:29 UTC
Latest CVE date: 22 Jul 2019, 15:15 UTC

Latest CVE reference: CVE-2019-1010235

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical frog_cms_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.77

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 9
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS frog_cms_project CVEs

These are the five CVEs with the highest CVSS scores for frog_cms_project, sorted by severity first and recency.

All CVEs for frog_cms_project

CVE-2019-1010235 frog_cms_project vulnerability CVSS: 3.5 22 Jul 2019, 15:15 UTC

Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.

CVE-2018-20778 frog_cms_project vulnerability CVSS: 4.3 11 Feb 2019, 02:29 UTC

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.

CVE-2018-20777 frog_cms_project vulnerability CVSS: 3.5 11 Feb 2019, 02:29 UTC

Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.

CVE-2018-20776 frog_cms_project vulnerability CVSS: 5.0 11 Feb 2019, 02:29 UTC

Frog CMS 0.9.5 provides a directory listing for a /public request.

CVE-2018-20775 frog_cms_project vulnerability CVSS: 6.5 11 Feb 2019, 02:29 UTC

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.

CVE-2018-20774 frog_cms_project vulnerability CVSS: 3.5 11 Feb 2019, 02:29 UTC

Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.

CVE-2018-20773 frog_cms_project vulnerability CVSS: 6.5 11 Feb 2019, 02:29 UTC

Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

CVE-2018-20772 frog_cms_project vulnerability CVSS: 6.5 11 Feb 2019, 02:29 UTC

Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.

CVE-2019-6243 frog_cms_project vulnerability CVSS: 4.3 12 Jan 2019, 02:29 UTC

Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).

CVE-2018-20680 frog_cms_project vulnerability CVSS: 3.5 09 Jan 2019, 17:29 UTC

Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.

CVE-2018-20448 frog_cms_project vulnerability CVSS: 3.5 25 Dec 2018, 16:29 UTC

Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.

CVE-2018-16374 frog_cms_project vulnerability CVSS: 3.5 03 Sep 2018, 00:29 UTC

Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.

CVE-2018-16373 frog_cms_project vulnerability CVSS: 4.0 03 Sep 2018, 00:29 UTC

Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.

CVE-2018-11098 frog_cms_project vulnerability CVSS: 6.5 15 May 2018, 01:29 UTC

An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.

CVE-2018-9992 frog_cms_project vulnerability CVSS: 3.5 11 Apr 2018, 06:29 UTC

Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.

CVE-2018-9991 frog_cms_project vulnerability CVSS: 3.5 11 Apr 2018, 06:29 UTC

Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.

CVE-2018-8908 frog_cms_project vulnerability CVSS: 6.8 31 Mar 2018, 22:29 UTC

An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.

CVE-2014-4912 frog_cms_project vulnerability CVSS: 7.5 22 Mar 2018, 04:29 UTC

An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.