Ctcms Project maintains a narrowly scoped content management system where vulnerabilities cluster around output encoding and template-handling issues, including code injection, path traversal, and incomplete filtering of special elements. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ctcms Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14731HIGH A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component | Dec 16, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-14730HIGH A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the comp | Dec 15, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-14729HIGH A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend | Dec 15, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-4545HIGH A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.ph | May 11, 2025 | 8.1 | 23 | NO | NO |
CVE-2024-1925HIGH A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipula | Feb 27, 2024 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ctcms Project.
Media articles that mention a CVE ID that affects a product developed by Ctcms Project — matched by CVE ID, not by vendor name.