Blackcat CMS is a modestly represented content-management system in the vulnerability landscape, notable for its presence among widely tracked web applications despite its focused product scope. The vendor's disclosures center on its single core product and reflect the input-handling and access-control exposures typical of web-based CMS platforms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blackcat Cms over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25453HIGH An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | Sep 15, 2020 | 8.8 | 40 | NO | YES |
CVE-2015-5079HIGH Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter. | Feb 28, 2018 | 7.5 | 36 | NO | YES |
CVE-2017-14050HIGH In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file. | Aug 31, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-14399HIGH In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .ph | Sep 12, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14048HIGH BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this c | Aug 31, 2017 | 8.8 | 26 | NO | NO |
CVE-2023-53892HIGH Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers | Dec 15, 2025 | 7.2 | 24 | NO | NO |
CVE-2017-13670MEDIUM In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a | Aug 31, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-9609MEDIUM Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/page | Jul 17, 2017 | 5.4 | 21 | NO | NO |
CVE-2023-53891MEDIUM Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript | Dec 15, 2025 | 5.4 | 20 | NO | NO |
CVE-2017-14049MEDIUM In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field. | Aug 31, 2017 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blackcat Cms.
Media articles that mention a CVE ID that affects a product developed by Blackcat Cms — matched by CVE ID, not by vendor name.