Cmseasy is a content-management system with a modestly sized vulnerability footprint concentrated in its single flagship product. The platform's recurring exposure centers on input-handling and access-control weaknesses endemic to web applications: path traversal, cross-site scripting, cross-site request forgery, code injection, and improper exposure of files or directories. These weakness classes reflect the challenge of securing dynamic content generation and user input sanitization in open-source CMS platforms, and the vendor's disclosures skew toward moderate severity outcomes. Defenders deploying this system should apply input validation and output encoding rigorously, restrict administrative interfaces, and treat available patches as a priority; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cmseasy over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34880CRITICAL cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to | Jun 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-42643HIGH cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this fil | May 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-1336HIGH A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in the library lib/admin/image_admi | Feb 16, 2025 | 8.1 | 25 | NO | NO |
CVE-2018-11679HIGH An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin. | Jun 2, 2018 | 8.8 | 25 | NO | NO |
CVE-2025-1335HIGH A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admin/file_admin.php. The manipulat | Feb 16, 2025 | 8.1 | 24 | NO | NO |
CVE-2024-0523CRITICAL A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/la | Jan 14, 2024 | 9.8 | 24 | NO | NO |
CVE-2025-15148HIGH A flaw has been found in CmsEasy up to 7.7.7. Affected is the function savetemp_action in the library /lib/admin/template_admin.php of the component Backend Template Management Pag | Dec 28, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-55910MEDIUM CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php. | Sep 19, 2025 | 6.3 | 22 | NO | NO |
CVE-2020-18406HIGH An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data. | Jun 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2021-42644MEDIUM cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file | May 17, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cmseasy.
Media articles that mention a CVE ID that affects a product developed by Cmseasy — matched by CVE ID, not by vendor name.