Auracms develops a compact suite of web-based content management and community modules, including its core CMS platform and forum and statistics components, with a narrow but prominently tracked presence in the vulnerability landscape. The vendor's disclosures recur consistently through application-layer input-handling weaknesses—SQL injection, path traversal, code injection, cross-site scripting, and cross-site request forgery—that are endemic to web applications lacking comprehensive input validation and output encoding. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code; defenders should prioritize patches for Auracms deployments and treat this vendor's advisories as requiring near-term remediation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Auracms over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0735HIGH SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter. | Feb 13, 2008 | 10.0 | 37 | NO | YES |
CVE-2007-4804HIGH Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, | Sep 11, 2007 | 7.5 | 34 | NO | YES |
CVE-2010-4774HIGH SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE | Mar 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2008-0811HIGH Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, an | Feb 19, 2008 | 7.5 | 32 | NO | YES |
CVE-2007-4905HIGH Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a fi | Sep 17, 2007 | 7.5 | 31 | NO | YES |
CVE-2008-3203HIGH js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter | Jul 17, 2008 | 7.5 | 29 | NO | YES |
CVE-2007-4908HIGH Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih param | Sep 17, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-0390HIGH stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat | Jan 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-4171HIGH SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter t | Aug 7, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-4886MEDIUM Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3 | Sep 14, 2007 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Auracms.
Media articles that mention a CVE ID that affects a product developed by Auracms — matched by CVE ID, not by vendor name.