Cmswing is a web content-management system with a narrow but prominent product footprint where vulnerabilities skew strongly toward critical-severity outcomes. The exposure concentrates in the core Cmswing product and recurs through application-layer weakness classes including SQL injection, cross-site scripting, argument injection, and insufficient password-hashing practices that are characteristic of web-application input handling and authentication. Defenders should prioritize patches for this vendor given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cmswing over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43736CRITICAL CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule | Mar 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43735CRITICAL CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. | Mar 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-20295CRITICAL An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands. | Feb 1, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-20296CRITICAL An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL comman | Feb 1, 2021 | 9.8 | 27 | NO | NO |
CVE-2020-20294CRITICAL An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands. | Feb 1, 2021 | 9.8 | 27 | NO | NO |
CVE-2019-7649HIGH global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing. | Feb 17, 2019 | 7.5 | 23 | NO | NO |
CVE-2020-24992MEDIUM There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module. | May 17, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-24993MEDIUM There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module. | May 17, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cmswing.
Media articles that mention a CVE ID that affects a product developed by Cmswing — matched by CVE ID, not by vendor name.