Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Croogo

First CVE: Oct 31, 2014Active for: 12 yearsTotal CVEs: 12
33.1
VTI Score
Medium

Croogo is a modestly represented content-management and publishing platform with a narrow product footprint that has been the subject of security research and public tooling development. The vendor's vulnerability profile concentrates in web application and file-handling layers, with recurring weaknesses including cross-site scripting, path traversal, HTTP request smuggling, and unrestricted file uploads that are typical of CMS platforms and reflect input-handling and resource-validation demands. Defenders deploying Croogo should prioritize patching for input-validation and upload-control flaws; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Croogo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2014
11 years ago
Most Recent CVE
Dec 26, 2025
210 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44673HIGH
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.
Mar 10, 20228.835NOYES
CVE-2024-29643CRITICAL
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
Apr 18, 20259.124NONO
CVE-2024-42718MEDIUM
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
Dec 26, 20256.523NONO
CVE-2014-8577MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter
Oct 31, 20144.322NOYES
CVE-2019-20789MEDIUM
Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
Apr 26, 20204.819NONO
CVE-2019-7170MEDIUM
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies.
Jan 29, 20194.819NONO
CVE-2019-7169MEDIUM
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/menus/menus/edit/3.
Jan 29, 20194.819NONO
CVE-2019-7168MEDIUM
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.
Jan 29, 20194.819NONO
CVE-2017-1000510MEDIUM
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
Feb 9, 20185.419NONO
CVE-2019-7173MEDIUM
A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.
Jan 29, 20194.815NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
83%
8%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown2 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High0 (0.0%)
Unknown2 (16.7%)
User Interaction
None3 (25.0%)
Unknown2 (16.7%)
Required7 (58.3%)
Privileges Required
Low3 (25.0%)
High6 (50.0%)
None1 (8.3%)
Unknown2 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Croogo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Croogo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Croogo's Products

View all 1 CNAs →

Top CWEs