Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

74cms

First CVE: Dec 25, 2018Active for: 8 yearsTotal CVEs: 36
49.7
VTI Score
TOP TARGET

74cms maintains a small footprint focused on content management and server software products, yet sits among the more prominent vendors in the landscape relative to its product scope. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven largely by recurring application-layer weaknesses in the core 74cmsse and 74cms products including SQL injection, cross-site scripting, code injection, and improper access controls that are typical of web-facing CMS implementations. The exposure pattern reflects the web-application nature of these products and their deployment in public-facing environments, where input-validation and output-encoding flaws translate directly into high-severity attack chains. Defenders should treat this vendor's security advisories as high-priority and maintain close inventory of affected CMS deployments; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 74cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2018
7 years ago
Most Recent CVE
May 6, 2025
444 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-29279CRITICAL
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.
Dec 2, 20209.871NOYES
CVE-2020-22209CRITICAL
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
Jun 16, 20219.844NOYES
CVE-2020-22208CRITICAL
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
Jun 16, 20219.844NOYES
CVE-2020-22211CRITICAL
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
Jun 16, 20219.843NOYES
CVE-2020-22210CRITICAL
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
Jun 16, 20219.843NOYES
CVE-2019-11374HIGH
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
Apr 20, 20198.843NOYES
CVE-2022-26271HIGH
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
Mar 28, 20227.537NOYES
CVE-2019-10684CRITICAL
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain
Apr 1, 20199.832NONO
CVE-2022-42154CRITICAL
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
Oct 17, 20229.830NONO
CVE-2020-35339CRITICAL
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attacker
Feb 17, 20219.829NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
39%
36%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (66.7%)
Unknown0 (0.0%)
Required12 (33.3%)
Privileges Required
Low6 (16.7%)
High1 (2.8%)
None29 (80.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
16.7% of CVEs· 97th percentile
ExploitDB
1 CVE
2.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 74cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 74cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 74cms's Products

View all 2 CNAs →

Top CWEs