Catfish CMS is a content-management system with a narrow product footprint centered on its core CMS and blog platforms, deployed in niche web-hosting and small-business environments. The disclosed vulnerabilities reflect application-layer exposure typical of web-facing CMS software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Catfish Cms over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45017HIGH Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the | Dec 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-18735HIGH A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | Oct 29, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-18734HIGH A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30. | Oct 29, 2018 | 8.8 | 26 | NO | NO |
CVE-2021-45018MEDIUM Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website t | Dec 15, 2021 | 6.1 | 22 | NO | NO |
CVE-2020-23962MEDIUM A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gong | Jun 23, 2021 | 6.1 | 20 | NO | NO |
CVE-2018-18736MEDIUM An XSS issue was discovered in catfish blog 2.0.33, related to "write source code." | Oct 29, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-18733MEDIUM An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999. | Oct 29, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-10023MEDIUM Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). | Apr 11, 2018 | 5.4 | 18 | NO | NO |
CVE-2018-13999MEDIUM Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator). | Jul 12, 2018 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Catfish Cms.
Media articles that mention a CVE ID that affects a product developed by Catfish Cms — matched by CVE ID, not by vendor name.