Cms.Tut.Su operates a focused content-management system, CMS ChainUK, with a vulnerability footprint concentrated in web-application input handling and access control. The recurring weakness classes—cross-site scripting, code injection, path traversal, and sensitive-information exposure—reflect the common parsing and authorization challenges in web-based CMS platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cms.Tut.Su over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2333HIGH Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu p | Jul 5, 2009 | 7.5 | 33 | NO | YES |
CVE-2009-2331HIGH Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to ad | Jul 5, 2009 | 7.5 | 30 | NO | YES |
CVE-2009-2332MEDIUM CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent folder name in the id parameter | Jul 5, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-2330MEDIUM Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu paramete | Jul 5, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cms.Tut.Su.
Media articles that mention a CVE ID that affects a product developed by Cms.Tut.Su — matched by CVE ID, not by vendor name.