Arcms Project maintains a focused content management system product where the recurring vulnerability signal centers on SQL injection, reflecting input-handling challenges in database-oriented applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arcms Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19558CRITICAL An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db | Nov 26, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-19557CRITICAL An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images. | Nov 26, 2018 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arcms Project.
Media articles that mention a CVE ID that affects a product developed by Arcms Project — matched by CVE ID, not by vendor name.