CVE-2018-10429: Cosmocms Cosmo
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.
Affected products
- Cosmocms Cosmo: version 1.0.0 only
Published 2018-04-26. Last modified 2026-06-17.