Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Automad

First CVE: Apr 29, 2022Active for: 4 yearsTotal CVEs: 8

Automad is a lightweight, flat-file content management system whose vulnerability profile concentrates in a single product and reflects the security challenges of web application frameworks handling user input and file uploads. The durable signal centers on application-layer weaknesses including cross-site scripting, file upload validation, cross-site request forgery, code injection, and server-side request forgery—issues endemic to CMS platforms where content authoring, template processing, and request handling intersect. Defenders deploying Automad should prioritize input sanitization, upload controls, and session management; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Automad over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 2022
4 years ago
Most Recent CVE
Aug 23, 2024
700 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-40400HIGH
An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.
Jul 19, 20248.824NONO
CVE-2023-7037HIGH
A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileController.php. The manipulation
Dec 21, 20238.823NONO
CVE-2021-37502MEDIUM
Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user.
Feb 3, 20235.420NONO
CVE-2022-1536MEDIUM
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the inpu
Apr 29, 20225.420NONO
CVE-2023-7035MEDIUM
A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.p
Dec 21, 20235.419NONO
CVE-2023-7038MEDIUM
A vulnerability was found in automad up to 1.10.9. It has been rated as problematic. This issue affects some unknown processing of the file /dashboard?controller=UserCollection::cr
Dec 21, 20236.518NONO
CVE-2024-40111MEDIUM
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript c
Aug 23, 20244.817NONO
CVE-2023-7036MEDIUM
A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollectionController.php of the component
Dec 21, 20235.417NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (25.0%)
Unknown0 (0.0%)
Required6 (75.0%)
Privileges Required
Low6 (75.0%)
High1 (12.5%)
None1 (12.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Automad.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Automad — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Automad's Products

View all 2 CNAs →

Top CWEs