CVE-2018-12971: Easycms

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.

Affected products

Published 2018-06-29. Last modified 2026-06-17.