Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Blackcat Cms

First CVE: Sep 12, 2014Active for: 12 yearsTotal CVEs: 38

Blackcat CMS is a modestly represented content-management system in the vulnerability landscape, notable for its presence among widely tracked web applications despite its focused product scope. The vendor's disclosures center on its single core product and reflect the input-handling and access-control exposures typical of web-based CMS platforms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Blackcat Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2014
11 years ago
Most Recent CVE
Dec 15, 2025
221 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25453HIGH
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Sep 15, 20208.840NOYES
CVE-2015-5079HIGH
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.
Feb 28, 20187.536NOYES
CVE-2017-14050HIGH
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.
Aug 31, 20178.827NONO
CVE-2017-14399HIGH
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .ph
Sep 12, 20178.826NONO
CVE-2017-14048HIGH
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this c
Aug 31, 20178.826NONO
CVE-2023-53892HIGH
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers
Dec 15, 20257.224NONO
CVE-2017-13670MEDIUM
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a
Aug 31, 20176.521NONO
CVE-2017-9609MEDIUM
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/page
Jul 17, 20175.421NONO
CVE-2023-53891MEDIUM
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript
Dec 15, 20255.420NONO
CVE-2017-14049MEDIUM
In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field.
Aug 31, 20175.420NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
68%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network18 (94.7%)
Unknown1 (5.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High0 (0.0%)
Unknown1 (5.3%)
User Interaction
None6 (31.6%)
Unknown1 (5.3%)
Required12 (63.2%)
Privileges Required
Low10 (52.6%)
High5 (26.3%)
None3 (15.8%)
Unknown1 (5.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Blackcat Cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Blackcat Cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Blackcat Cms's Products

View all 2 CNAs →

Top CWEs