Bluecms Project's vulnerability profile concentrates on a single content-management system that, despite a narrow product footprint, ranks among the more prominent vendors in the landscape and skews strongly toward critical-severity outcomes. The recurring exposure centers on SQL injection, improper input validation, and inadequate access controls—characteristic flaws of web application frameworks handling user input and resource permissions. Defenders should treat this vendor's advisories as high-priority within environments running Bluecms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluecms Project over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37113CRITICAL Bluecms 1.6 has SQL injection in line 132 of admin/area.php | Aug 23, 2022 | 9.8 | 38 | NO | NO |
CVE-2023-33734CRITICAL BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | May 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-37112CRITICAL BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | Aug 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-37111CRITICAL BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | Aug 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-19853CRITICAL BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-10262CRITICAL A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resul | Mar 28, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16432CRITICAL BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. | Sep 4, 2018 | 9.8 | 29 | NO | NO |
CVE-2022-27962CRITICAL Bluecms 1.6 has a SQL injection vulnerability at cooike. | May 3, 2022 | 9.8 | 28 | NO | NO |
CVE-2019-9594CRITICAL BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | Mar 6, 2019 | 9.8 | 24 | NO | NO |
CVE-2010-4897HIGH SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action. | Oct 8, 2011 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluecms Project.
Media articles that mention a CVE ID that affects a product developed by Bluecms Project — matched by CVE ID, not by vendor name.