Aerocms Project maintains a content-management system that, despite a narrow product focus, ranks among the more prominent CMS platforms in the vulnerability landscape. The vendor's vulnerability profile concentrates consistently around web-application input-handling and file-upload mechanisms, with recurring weakness classes including SQL injection, cross-site scripting, unrestricted file uploads, cross-site request forgery, and path traversal that are characteristic of server-side web frameworks lacking robust input validation and access controls. These weaknesses reflect the parser and request-routing demands of web-facing CMS software and recur across the product line, indicating structural exposure areas rather than isolated incidents. Defenders should prioritize input-validation and upload-control patches for this vendor's releases and consider restricting administrative access where feasible; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aerocms Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50895CRITICAL Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based | Jan 13, 2026 | 9.8 | 34 | NO | NO |
CVE-2022-38305HIGH AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code | Sep 13, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-38812MEDIUM AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. | Aug 31, 2022 | 6.5 | 26 | NO | YES |
CVE-2022-45329HIGH AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. | Nov 29, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45330HIGH AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database informati | Nov 22, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-46137HIGH AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1. | Dec 16, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-46135HIGH In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server. | Dec 16, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-46051HIGH The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks. | Dec 13, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-46059MEDIUM AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | Dec 13, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-46061MEDIUM AeroCMS v0.0.1 is vulnerable to ClickJacking. | Dec 13, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aerocms Project.
Media articles that mention a CVE ID that affects a product developed by Aerocms Project — matched by CVE ID, not by vendor name.