← Vulnerability feed

Vulnerability record · CVE-2015-2678 · published 23 March 2015

CVE-2015-2678: Genixcms cross-site scripting vulnerability

GGenixcms · Genixcms

Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.

4.3 CVSS 2.0 Medium EPSS 5.4% · top 7.6% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2017-8827Genixcms improper authentication vulnerabilityforgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl…EPSS 1.6%8.8CVE-2017-14763Genixcms vulnerabilityIn the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.EPSS 1.4%8.8CVE-2017-14764Genixcms code injection vulnerabilityIn the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.EPSS 1.5%8.8CVE-2017-8377Genixcms sql injection vulnerabilityGeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.EPSS 1.5%7.5CVE-2015-2679Genixcms sql injection vulnerabilityMultiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page …EPSS 5.6%7.3CVE-2016-10096Genixcms sql injection vulnerabilitySQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation par…EPSS 1.6%7.2CVE-2017-5346Genixcms sql injection vulnerabilitySQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbi…EPSS 1.6%6.1CVE-2017-17431Genixcms cross-site scripting vulnerabilityGeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-201…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2015-2678), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.