Canto is a modest but critically exposed digital asset management platform whose vulnerability footprint skews strongly toward critical-severity outcomes and frequently acquires public exploit code. The recurring exposure centers on server-side request forgery, PHP remote file inclusion, code injection, and command injection—all consequence of inadequate input validation and control flow handling—making the platform vulnerable to remote code execution and unauthorized server compromise. Defenders should treat this vendor's advisories as high-priority for any internet-exposed deployment; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Canto over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28976MEDIUM The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes | Nov 30, 2020 | 5.3 | 52 | NO | YES |
CVE-2023-3452CRITICAL The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers | Aug 12, 2023 | 9.8 | 44 | NO | YES |
CVE-2020-28977MEDIUM The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/l | Nov 30, 2020 | 5.3 | 35 | NO | YES |
CVE-2024-4936CRITICAL The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthentica | Jun 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-28978MEDIUM The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/l | Nov 30, 2020 | 5.3 | 29 | NO | YES |
CVE-2024-25096CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. | Apr 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2013-7416HIGH canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed. | Dec 3, 2014 | 7.5 | 25 | NO | NO |
CVE-2022-40305CRITICAL A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified ot | Sep 9, 2022 | 9.8 | 24 | NO | NO |
CVE-2020-24063HIGH The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. | Nov 10, 2020 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Canto.
Media articles that mention a CVE ID that affects a product developed by Canto — matched by CVE ID, not by vendor name.