Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cmswing

First CVE: Feb 17, 2019Active for: 7 yearsTotal CVEs: 8

Cmswing is a web content-management system with a narrow but prominent product footprint where vulnerabilities skew strongly toward critical-severity outcomes. The exposure concentrates in the core Cmswing product and recurs through application-layer weakness classes including SQL injection, cross-site scripting, argument injection, and insufficient password-hashing practices that are characteristic of web-application input handling and authentication. Defenders should prioritize patches for this vendor given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cmswing over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2019
7 years ago
Most Recent CVE
Mar 23, 2022
1,584 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43736CRITICAL
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
Mar 23, 20229.831NONO
CVE-2021-43735CRITICAL
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
Mar 23, 20229.830NONO
CVE-2020-20295CRITICAL
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
Feb 1, 20219.829NONO
CVE-2020-20296CRITICAL
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL comman
Feb 1, 20219.827NONO
CVE-2020-20294CRITICAL
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
Feb 1, 20219.827NONO
CVE-2019-7649HIGH
global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.
Feb 17, 20197.523NONO
CVE-2020-24992MEDIUM
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.
May 17, 20215.419NONO
CVE-2020-24993MEDIUM
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.
May 17, 20215.418NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
25%
13%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cmswing.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cmswing — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cmswing's Products

View all 1 CNAs →

Top CWEs