Articlecms Project maintains a content management system that, despite its narrow product scope, operates across a modestly distributed deployment base and presents a web-application attack surface. The durable signal from its vulnerability profile centers on input-handling and file-upload mechanisms, with recurring exposures in cross-site scripting and unrestricted file-upload weaknesses that are characteristic of web-publishing platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Articlecms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28063CRITICAL A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. | May 13, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-20092CRITICAL File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which | May 13, 2021 | 9.8 | 28 | NO | NO |
CVE-2018-19469MEDIUM ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. | Nov 23, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-12339MEDIUM ArticleCMS through 2017-02-19 has XSS via an "add an article" action. | Jun 13, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Articlecms Project.
Media articles that mention a CVE ID that affects a product developed by Articlecms Project — matched by CVE ID, not by vendor name.