Cmsuno Project maintains a content-management system whose vulnerability footprint, while narrowly scoped to a single product, skews toward serious outcomes with an elevated share reaching critical severity and a strong tendency toward public exploit availability. The recurring weakness classes—code injection, cross-site scripting, and cross-site request forgery—are characteristic of web application input-handling and session-management flaws and reflect the attack surface inherent to a browser-facing CMS. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cmsuno Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25538HIGH An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can | Nov 13, 2020 | 8.8 | 42 | NO | YES |
CVE-2020-25557HIGH In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacke | Nov 13, 2020 | 8.8 | 38 | NO | YES |
CVE-2020-15600MEDIUM An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. | Jul 7, 2020 | 6.5 | 33 | NO | YES |
CVE-2021-40889CRITICAL CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username i | Oct 11, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-36654MEDIUM CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme. | Aug 3, 2021 | 5.4 | 28 | NO | YES |
CVE-2018-15567MEDIUM CMSUno before 1.5.3 has XSS via the title field. | Aug 20, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cmsuno Project.
Media articles that mention a CVE ID that affects a product developed by Cmsuno Project — matched by CVE ID, not by vendor name.