← Vulnerability feed

Vulnerability record · CVE-2017-14764 · published 27 September 2017

CVE-2017-14764: Genixcms code injection vulnerability

GGenixcms · Genixcms

In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

8.8 CVSS 3.0 High EPSS 1.5% · top 26.2% CWE-94 · Code injection
8.8CVSS 3.0 base score, v2 6.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14764 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2017-8827Genixcms improper authentication vulnerabilityforgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl…EPSS 1.6%8.8CVE-2017-14763Genixcms vulnerabilityIn the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.EPSS 1.4%8.8CVE-2017-8377Genixcms sql injection vulnerabilityGeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.EPSS 1.5%7.5CVE-2015-2679Genixcms sql injection vulnerabilityMultiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page …EPSS 5.6%7.3CVE-2016-10096Genixcms sql injection vulnerabilitySQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation par…EPSS 1.6%7.2CVE-2017-5346Genixcms sql injection vulnerabilitySQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbi…EPSS 1.6%6.1CVE-2017-17431Genixcms cross-site scripting vulnerabilityGeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-201…EPSS 0.68%6.1CVE-2017-14761Genixcms cross-site scripting vulnerabilityIn GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2017-14764), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.