Couchcms operates a focused content-management system platform with a vulnerability profile centered on access-control and information-disclosure issues, including authorization bypasses, path traversal, open redirects, and exposure of sensitive data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Couchcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7662MEDIUM Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php. | Mar 4, 2018 | 5.3 | 51 | NO | YES |
CVE-2026-29002HIGH CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in | Apr 10, 2026 | 7.2 | 27 | NO | NO |
CVE-2025-67004MEDIUM ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the | Jan 9, 2026 | 6.5 | 24 | NO | NO |
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation | Dec 22, 2025 | 3.7 | 18 | NO | NO |
CVE-2023-41609MEDIUM An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL. | Sep 11, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Couchcms.
Media articles that mention a CVE ID that affects a product developed by Couchcms — matched by CVE ID, not by vendor name.