Classcms Project maintains a web content management system where the recurring vulnerability signal centers on input-handling and file-upload weaknesses, particularly cross-site scripting and unrestricted file uploads that are characteristic of web application frameworks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Classcms Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45966CRITICAL here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-57099CRITICAL ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, all | Feb 3, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-48180CRITICAL ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code. | Oct 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-25581HIGH Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt fil | Mar 18, 2022 | 7.8 | 26 | NO | NO |
CVE-2024-12666HIGH A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPos | Dec 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-8144MEDIUM A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo H | Aug 25, 2024 | 6.1 | 20 | NO | NO |
CVE-2022-25582MEDIUM A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in | Mar 25, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-8145MEDIUM A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the compo | Aug 25, 2024 | 4.8 | 18 | NO | NO |
CVE-2024-6932MEDIUM A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:i | Jul 20, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-12503MEDIUM A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model | Dec 12, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Classcms Project.
Media articles that mention a CVE ID that affects a product developed by Classcms Project — matched by CVE ID, not by vendor name.