74cms maintains a small footprint focused on content management and server software products, yet sits among the more prominent vendors in the landscape relative to its product scope. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven largely by recurring application-layer weaknesses in the core 74cmsse and 74cms products including SQL injection, cross-site scripting, code injection, and improper access controls that are typical of web-facing CMS implementations. The exposure pattern reflects the web-application nature of these products and their deployment in public-facing environments, where input-validation and output-encoding flaws translate directly into high-severity attack chains. Defenders should treat this vendor's security advisories as high-priority and maintain close inventory of affected CMS deployments; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 74cms over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29279CRITICAL PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution. | Dec 2, 2020 | 9.8 | 71 | NO | YES |
CVE-2020-22209CRITICAL SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. | Jun 16, 2021 | 9.8 | 44 | NO | YES |
CVE-2020-22208CRITICAL SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. | Jun 16, 2021 | 9.8 | 44 | NO | YES |
CVE-2020-22211CRITICAL SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. | Jun 16, 2021 | 9.8 | 43 | NO | YES |
CVE-2020-22210CRITICAL SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. | Jun 16, 2021 | 9.8 | 43 | NO | YES |
CVE-2019-11374HIGH 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | Apr 20, 2019 | 8.8 | 43 | NO | YES |
CVE-2022-26271HIGH 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php. | Mar 28, 2022 | 7.5 | 37 | NO | YES |
CVE-2019-10684CRITICAL Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain | Apr 1, 2019 | 9.8 | 32 | NO | NO |
CVE-2022-42154CRITICAL An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file. | Oct 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-35339CRITICAL In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attacker | Feb 17, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 74cms.
Media articles that mention a CVE ID that affects a product developed by 74cms — matched by CVE ID, not by vendor name.