Articlecms

Vendor:

First CVE: Jun 13, 2018 · Active for 8 years

4
Total CVEs
More Total CVEs than 72% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Articlecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2018
8 years ago
Most Recent CVE
May 13, 2021
1,898 days ago

CVE Severity & Scoring

Articlecms4 CVEs
All CVEs352,294 CVEs
MediumCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None3 (75.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
May 13, 20219.829NONO
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which
May 13, 20219.828NONO
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
Nov 23, 20186.121NONO
ArticleCMS through 2017-02-19 has XSS via an "add an article" action.
Jun 13, 20185.419NONO

Exploit Exposure

Signals from CVEs in this product scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (4 CVEs).

Media Mentions

Signals from CVEs in this product scope (4 CVEs).

Top CNAs Publishing CVEs For Articlecms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.019.81.3%00