taocms vulnerabilities
CVEs whose affected-version data names the taocms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2022-36262Critical· 9.8An issue was discovered in taocms 3.0.2
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
▾ Midnighttaogogo · taocmsEPSS 1.8%via NVD
CVE-2022-25578Critical· 9.8taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
▾ Midnighttaogogo · taocmsEPSS 1.8%via NVD