Automad is a lightweight, flat-file content management system whose vulnerability profile concentrates in a single product and reflects the security challenges of web application frameworks handling user input and file uploads. The durable signal centers on application-layer weaknesses including cross-site scripting, file upload validation, cross-site request forgery, code injection, and server-side request forgery—issues endemic to CMS platforms where content authoring, template processing, and request handling intersect. Defenders deploying Automad should prioritize input sanitization, upload controls, and session management; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Automad over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40400HIGH An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file. | Jul 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-7037HIGH A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileController.php. The manipulation | Dec 21, 2023 | 8.8 | 23 | NO | NO |
CVE-2021-37502MEDIUM Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user. | Feb 3, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-1536MEDIUM A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the inpu | Apr 29, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-7035MEDIUM A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.p | Dec 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-7038MEDIUM A vulnerability was found in automad up to 1.10.9. It has been rated as problematic. This issue affects some unknown processing of the file /dashboard?controller=UserCollection::cr | Dec 21, 2023 | 6.5 | 18 | NO | NO |
CVE-2024-40111MEDIUM A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript c | Aug 23, 2024 | 4.8 | 17 | NO | NO |
CVE-2023-7036MEDIUM A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component | Dec 21, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Automad.
Media articles that mention a CVE ID that affects a product developed by Automad — matched by CVE ID, not by vendor name.