8cms operates a narrowly scoped content-management platform centered on the LJCMS product, with the durable vulnerability signal concentrated on web-application input handling and access control, specifically unrestricted file uploads, SQL injection, and improper authentication-attempt restrictions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 8cms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21237CRITICAL An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks. | Dec 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-20979CRITICAL An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code. | Aug 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-20735CRITICAL File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter. | Jun 20, 2023 | 9.8 | 26 | NO | NO |
CVE-2020-20583HIGH A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information. | Jul 8, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 8cms.
Media articles that mention a CVE ID that affects a product developed by 8cms — matched by CVE ID, not by vendor name.