Contenido is a narrowly scoped content management system where vulnerabilities cluster around web application input handling and code generation. The recurring exposure reflects input-validation and cross-site scripting weaknesses that are characteristic of CMS platforms handling user-supplied content, alongside code-injection conditions that arise in templating and dynamic execution contexts. Vulnerabilities in this product frequently acquire public exploit code; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contenido over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2912HIGH Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) | Jun 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2911MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, | Jun 30, 2008 | 4.3 | 21 | NO | YES |
CVE-2006-5380HIGH Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/ | Oct 18, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-4132HIGH Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it i | Dec 9, 2005 | 7.5 | 19 | NO | NO |
CVE-2006-5381MEDIUM Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a di | Oct 18, 2006 | 5.0 | 15 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to injec | Dec 31, 2014 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contenido.
Media articles that mention a CVE ID that affects a product developed by Contenido — matched by CVE ID, not by vendor name.