nukeviet CVE Vulnerabilities & Metrics

Focus on nukeviet vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About nukeviet Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nukeviet. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total nukeviet CVEs: 10
Earliest CVE date: 23 Jun 2020, 20:15 UTC
Latest CVE date: 13 Nov 2022, 10:15 UTC

Latest CVE reference: CVE-2022-3975

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical nukeviet CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.32

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 4
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS nukeviet CVEs

These are the five CVEs with the highest CVSS scores for nukeviet, sorted by severity first and recency.

All CVEs for nukeviet

CVE-2022-3975 nukeviet vulnerability CVSS: 0 13 Nov 2022, 10:15 UTC

A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the function filterAttr of the file vendor/vinades/nukeviet/Core/Request.php of the component Data URL Handler. The manipulation of the argument attrSubSet leads to cross site scripting. The attack may be launched remotely. Upgrading to version 4.5 is able to address this issue. The name of the patch is 0b3197fad950bb3383e83039a8ee4c9509b3ce02. It is recommended to upgrade the affected component. VDB-213554 is the identifier assigned to this vulnerability.

CVE-2022-30874 nukeviet vulnerability CVSS: 3.5 21 Jun 2022, 15:15 UTC

There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.

CVE-2020-22765 nukeviet vulnerability CVSS: 4.3 30 Jul 2021, 14:15 UTC

Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.

CVE-2020-21809 nukeviet vulnerability CVSS: 7.5 30 Jul 2021, 14:15 UTC

SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.

CVE-2020-21808 nukeviet vulnerability CVSS: 7.5 30 Jul 2021, 14:15 UTC

SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

CVE-2019-7726 nukeviet vulnerability CVSS: 7.5 31 Dec 2020, 05:15 UTC

modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).

CVE-2019-7725 nukeviet vulnerability CVSS: 7.5 31 Dec 2020, 05:15 UTC

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).

CVE-2020-13157 nukeviet vulnerability CVSS: 4.3 23 Jun 2020, 20:15 UTC

modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.

CVE-2020-13156 nukeviet vulnerability CVSS: 4.3 23 Jun 2020, 20:15 UTC

modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

CVE-2020-13155 nukeviet vulnerability CVSS: 6.8 23 Jun 2020, 20:15 UTC

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.