Creatiwity's vulnerability footprint centers on WityCMS, a modestly represented web content management system, where disclosures cluster around classic application-layer input-handling and file-upload weaknesses including cross-site scripting, SQL injection, cross-site request forgery, improper input validation, and unrestricted file uploads. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, consistent with the attack surface of web-facing administrative interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Creatiwity over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14029HIGH CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field. | Jul 13, 2018 | 8.8 | 35 | NO | YES |
CVE-2018-11512MEDIUM Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attack | May 28, 2018 | 4.8 | 29 | NO | YES |
CVE-2018-12065CRITICAL A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP | Jun 8, 2018 | 9.8 | 28 | NO | NO |
CVE-2022-29725HIGH An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file. | Jun 2, 2022 | 8.8 | 27 | NO | NO |
CVE-2018-16250MEDIUM The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first name" and "last name" parameters. | Jun 20, 2019 | 5.4 | 19 | NO | NO |
CVE-2018-16251MEDIUM A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input parameters are filtered, e.g., the /admin/user/users Nickname, | Jun 20, 2019 | 4.3 | 18 | NO | NO |
CVE-2018-16776MEDIUM wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. | Sep 10, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Creatiwity.
Media articles that mention a CVE ID that affects a product developed by Creatiwity — matched by CVE ID, not by vendor name.