Cltphp is a niche content-management or web-application framework that presents a concentrated vulnerability profile despite modest overall volume. Its disclosures cluster around input-handling and file-upload weaknesses—path traversal, cross-site scripting, unrestricted file upload, and improper input validation—that are characteristic of server-side web applications with insufficient sanitization, and vulnerabilities affecting the vendor skew strongly toward critical severity. Defenders should treat framework updates for this product as security-relevant; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cltphp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30264CRITICAL CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update. | May 4, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-30268CRITICAL CLTPHP <=6.0 is vulnerable to Improper Input Validation. | May 4, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-30266HIGH CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. | Apr 26, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-30269HIGH CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php. | Apr 26, 2023 | 8.1 | 25 | NO | NO |
CVE-2022-1085MEDIUM A vulnerability was found in CLTPHP up to 6.0. It has been declared as problematic. Affected by this vulnerability is the POST Parameter Handler. The manipulation leads to cross si | Mar 29, 2022 | 6.1 | 24 | NO | NO |
CVE-2023-30265MEDIUM CLTPHP <=6.0 is vulnerable to Directory Traversal. | Apr 26, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-30267MEDIUM CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php. | Apr 26, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cltphp.
Media articles that mention a CVE ID that affects a product developed by Cltphp — matched by CVE ID, not by vendor name.