Aptsys's vulnerability footprint centers on its Gems CMS Backend product and is characterized by application-layer weaknesses spanning information disclosure, authentication bypass, and SQL injection. The recurring issues reflect common risks in web-facing content-management systems, particularly around input handling, access control, and sensitive data exposure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aptsys over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52024CRITICAL A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs | Jan 23, 2026 | 9.4 | 36 | NO | NO |
CVE-2025-52025CRITICAL An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user inp | Jan 23, 2026 | 9.4 | 32 | NO | NO |
CVE-2025-52026HIGH An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint ret | Jan 23, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-52023MEDIUM A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file p | Jan 23, 2026 | 5.3 | 25 | NO | NO |
CVE-2025-52022MEDIUM A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal fi | Jan 23, 2026 | 5.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aptsys.
Media articles that mention a CVE ID that affects a product developed by Aptsys — matched by CVE ID, not by vendor name.