Alfasado's vulnerability profile concentrates in PowerCMS, a content management platform among the more prominent in its market, where disclosures skew toward serious outcomes with a meaningful share reaching critical severity. The recurring weakness classes—including cross-site scripting, path traversal, OS command injection, open redirect, and CSV formula injection—reflect the input-handling and output-encoding demands of a web-based publishing system. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alfasado over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33941CRITICAL PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitr | Sep 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-20850CRITICAL PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execut | Nov 24, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-54757HIGH Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may | Jul 31, 2025 | 8.0 | 25 | NO | NO |
CVE-2025-54752HIGH Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and op | Jul 31, 2025 | 8.0 | 25 | NO | NO |
CVE-2025-46359HIGH A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by restoring a crafted backup file. | Jul 31, 2025 | 7.2 | 25 | NO | NO |
CVE-2025-41396MEDIUM A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user. | Jul 31, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-36563MEDIUM Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesses a crafted URL, an arbitrary script may be executed on the | Jul 31, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-41391MEDIUM Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser. | Jul 31, 2025 | 5.4 | 19 | NO | NO |
CVE-2019-6020MEDIUM Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect u | Dec 26, 2019 | 6.1 | 19 | NO | NO |
CVE-2023-50297MEDIUM Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted | Dec 26, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alfasado.
Media articles that mention a CVE ID that affects a product developed by Alfasado — matched by CVE ID, not by vendor name.