Anantasoft develops a focused line of content management systems, principally Gazelle CMS and Ananta CMS variants, where the vulnerability profile centers on web application security boundaries including path traversal, sensitive information exposure, code injection, and cross-site scripting. These weakness classes reflect the input-handling and template-processing demands of CMS platforms and carry a marked tendency toward public exploit availability. Defenders should monitor this vendor's releases and treat CMS instances as requiring close input validation controls; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anantasoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3182MEDIUM Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file | Sep 11, 2009 | 6.8 | 30 | NO | YES |
CVE-2009-3180HIGH Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php. | Sep 11, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-6665MEDIUM change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code inj | Apr 8, 2009 | 6.8 | 26 | NO | YES |
CVE-2009-3181MEDIUM Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a dire | Sep 11, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-3171MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user paramet | Sep 11, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-3167MEDIUM Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) | Sep 11, 2009 | 4.3 | 21 | NO | YES |
CVE-2011-3702MEDIUM Ananta Gazelle 1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstr | Sep 23, 2011 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anantasoft.
Media articles that mention a CVE ID that affects a product developed by Anantasoft — matched by CVE ID, not by vendor name.