Clippercms is a modestly represented content-management platform whose vulnerability profile centers on web-application attack surface classes endemic to systems handling user input and file uploads. The disclosed vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, with recurring weaknesses including cross-site scripting, server-side request forgery, cross-site request forgery, session fixation, and unrestricted file upload—patterns typical of CMS platforms where input validation, request authenticity, and file-handling controls are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clippercms over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19135HIGH ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with t | Nov 11, 2018 | 8.8 | 38 | NO | YES |
CVE-2022-41497CRITICAL ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-41495CRITICAL ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-11332MEDIUM Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrar | May 24, 2018 | 4.8 | 26 | NO | YES |
CVE-2018-11571HIGH ClipperCMS 1.3.3 allows Session Fixation. | May 31, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-19424HIGH ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files. | Nov 21, 2018 | 7.2 | 24 | NO | NO |
CVE-2018-12101MEDIUM CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields. | Aug 15, 2019 | 5.4 | 19 | NO | NO |
CVE-2018-13106MEDIUM ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI. | Jul 3, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-11572MEDIUM ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI. | May 31, 2018 | 5.4 | 18 | NO | NO |
CVE-2018-13998MEDIUM ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users. | Jul 12, 2018 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clippercms.
Media articles that mention a CVE ID that affects a product developed by Clippercms — matched by CVE ID, not by vendor name.