Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Anchorcms

First CVE: Dec 2, 2014Active for: 12 yearsTotal CVEs: 13
39.0
VTI Score
Medium

Anchorcms develops a lightweight, open-source content management system that, despite a narrow product scope, occupies a niche in the web-application landscape and has attracted public exploit tooling for its vulnerabilities. The vendor's disclosures cluster around input-handling and web-tier weaknesses including cross-site scripting, cross-site request forgery, code injection, and sensitive-information exposure, reflecting the template-rendering and user-input processing demands of a CMS platform. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Anchorcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2014
11 years ago
Most Recent CVE
Jun 9, 2025
410 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7251CRITICAL
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many conn
Feb 19, 20189.885NOYES
CVE-2020-23342HIGH
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
Jan 19, 20218.844NOYES
CVE-2025-46041MEDIUM
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interfac
Jun 9, 20255.428NOYES
CVE-2024-37732MEDIUM
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
Jun 24, 20246.124NONO
CVE-2024-29499HIGH
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
Mar 22, 20247.421NONO
CVE-2021-44116MEDIUM
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to
Dec 15, 20216.121NONO
CVE-2015-5687HIGH
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object
Oct 5, 20157.520NONO
CVE-2022-25576MEDIUM
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delet
Mar 24, 20224.519NONO
CVE-2015-5060MEDIUM
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
Sep 7, 20176.117NONO
CVE-2014-9182MEDIUM
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
Dec 2, 20144.317NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown2 (15.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High0 (0.0%)
Unknown2 (15.4%)
User Interaction
None2 (15.4%)
Unknown2 (15.4%)
Required9 (69.2%)
Privileges Required
Low3 (23.1%)
High3 (23.1%)
None5 (38.5%)
Unknown2 (15.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 96th percentile
ExploitDB
3 CVEs
23.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Anchorcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Anchorcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Anchorcms's Products

View all 1 CNAs →

Top CWEs