Back to Database
Status published
Medium
CVE-2018-16636
Nucleus CMS 3.70 allows HTML Injection via the index.php body...
Vulnerability Description
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16636
Credits & Attribution
No credits recorded in the NVD database.
References
More from nucleuscms
View All →CVE-2021-37770
Nucleus CMS v3.71 is affected by a file upload vulnerability....
High
7.2
CVE-2020-21474
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker...
Unknown
0
CVE-2015-5454
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers...
Medium
4.3
CVE-2011-3760
Nucleus 3.61 allows remote attackers to obtain sensitive information via...
Medium
5
Affected Vendor
nucleuscms
View all reports →Affected Software
nucleus cms
Vulnerable Versions:
3.70
Timeline
Official Publish:
December 10th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.