Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Classcms

First CVE: Mar 18, 2022Active for: 4 yearsTotal CVEs: 11

Classcms is a niche web content management system whose vulnerability profile concentrates on application-layer input-handling and file-upload risks, including cross-site scripting, code injection, file-upload validation, and privilege-handling flaws. These vulnerabilities skew toward serious outcomes, reflecting the typical risk surface of web applications exposed to untrusted user input and administrative workflows. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 90% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Classcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2022
4 years ago
Most Recent CVE
Feb 3, 2025
537 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-45966CRITICAL
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
Dec 22, 20229.831NONO
CVE-2024-57099CRITICAL
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, all
Feb 3, 20259.830NONO
CVE-2024-48180CRITICAL
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
Oct 16, 20249.826NONO
CVE-2022-25581HIGH
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt fil
Mar 18, 20227.826NONO
CVE-2024-12666HIGH
A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPos
Dec 16, 20248.824NONO
CVE-2024-8144MEDIUM
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo H
Aug 25, 20246.120NONO
CVE-2022-25582MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in
Mar 25, 20225.420NONO
CVE-2024-8145MEDIUM
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the compo
Aug 25, 20244.818NONO
CVE-2024-6932MEDIUM
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:i
Jul 20, 20245.418NONO
CVE-2024-12503MEDIUM
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model
Dec 12, 20244.816NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
18%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low3 (27.3%)
High3 (27.3%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Classcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Classcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Classcms's Products

View all 2 CNAs →

Top CWEs