Croogo is a modestly represented content-management and publishing platform with a narrow product footprint that has been the subject of security research and public tooling development. The vendor's vulnerability profile concentrates in web application and file-handling layers, with recurring weaknesses including cross-site scripting, path traversal, HTTP request smuggling, and unrestricted file uploads that are typical of CMS platforms and reflect input-handling and resource-validation demands. Defenders deploying Croogo should prioritize patching for input-validation and upload-control flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Croogo over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44673HIGH A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script. | Mar 10, 2022 | 8.8 | 35 | NO | YES |
CVE-2024-29643CRITICAL An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component. | Apr 18, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-42718MEDIUM A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter. | Dec 26, 2025 | 6.5 | 23 | NO | NO |
CVE-2014-8577MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter | Oct 31, 2014 | 4.3 | 22 | NO | YES |
CVE-2019-20789MEDIUM Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies. | Apr 26, 2020 | 4.8 | 19 | NO | NO |
CVE-2019-7170MEDIUM A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies. | Jan 29, 2019 | 4.8 | 19 | NO | NO |
CVE-2019-7169MEDIUM A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/menus/menus/edit/3. | Jan 29, 2019 | 4.8 | 19 | NO | NO |
CVE-2019-7168MEDIUM A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog. | Jan 29, 2019 | 4.8 | 19 | NO | NO |
CVE-2017-1000510MEDIUM Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code. | Feb 9, 2018 | 5.4 | 19 | NO | NO |
CVE-2019-7173MEDIUM A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4. | Jan 29, 2019 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Croogo.
Media articles that mention a CVE ID that affects a product developed by Croogo — matched by CVE ID, not by vendor name.