Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Appcms

First CVE: Mar 6, 2019Active for: 7 yearsTotal CVEs: 6

Appcms is a focused web content-management product where vulnerabilities concentrate in application-layer input handling, particularly cross-site scripting and SQL injection flaws that reflect the risks inherent to user-supplied data processing in web platforms. The vendor's disclosures frequently acquire public exploit code, making timely patching important for deployed instances. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Appcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2019
7 years ago
Most Recent CVE
Jan 23, 2022
1,643 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-45380MEDIUM
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
Jan 23, 20226.125NOYES
CVE-2020-36007MEDIUM
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
Jun 3, 20216.121NONO
CVE-2020-36005MEDIUM
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
Jun 3, 20216.521NONO
CVE-2020-36006MEDIUM
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
Jun 3, 20216.520NONO
CVE-2020-36004MEDIUM
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
Jun 3, 20216.520NONO
CVE-2019-9595MEDIUM
AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
Mar 6, 20196.117NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High2 (33.3%)
None3 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Appcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Appcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Appcms's Products

View all 1 CNAs →

Top CWEs