CVE-2018-16774: Hongcms Project Hongcms

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.

Affected products

Published 2018-09-10. Last modified 2026-06-17.