Aspcms is a niche content management system with a focused product portfolio, where its reported vulnerabilities center on the core platform. The durable signal reflects application-layer input-handling weaknesses, particularly improper input validation, which are characteristic of web-facing CMS implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aspcms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15888CRITICAL An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered with the super administrators G | Aug 26, 2018 | 9.8 | 30 | NO | NO |
CVE-2008-6353HIGH SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-5260MEDIUM ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and passw | Oct 6, 2007 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aspcms.
Media articles that mention a CVE ID that affects a product developed by Aspcms — matched by CVE ID, not by vendor name.