Cuppacms is a modestly represented content-management system whose vulnerability profile, despite a narrow product scope, sits among the more prominent in the landscape due to the centrality of web applications to modern infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the web-application attack surface and the relative maturity of exploitation tooling for common CMS weaknesses. The exposure recurs persistently through input-handling and code-execution weakness classes including SQL injection, cross-site scripting, unrestricted file upload, code injection, and inclusion of untrusted functionality—each a durable class in web-application security that enables direct compromise of hosted content and underlying systems. Defenders deploying this CMS should treat advisories as high-priority, maintain strict application-layer controls, and segregate instances from trusted networks; live severity, exploitation, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cuppacms over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37190HIGH CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php. | Sep 13, 2022 | 8.8 | 65 | NO | YES |
CVE-2022-27985CRITICAL CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. | Apr 26, 2022 | 9.8 | 49 | NO | YES |
CVE-2022-27984CRITICAL CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php. | Apr 26, 2022 | 9.8 | 47 | NO | YES |
CVE-2022-38296CRITICAL Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | Sep 12, 2022 | 9.8 | 43 | NO | YES |
CVE-2022-25486HIGH CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. | Mar 15, 2022 | 7.8 | 40 | NO | YES |
CVE-2022-25485HIGH CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. | Mar 15, 2022 | 7.8 | 38 | NO | YES |
CVE-2022-24265HIGH Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter. | Jan 31, 2022 | 7.5 | 38 | NO | YES |
CVE-2022-24266HIGH Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter. | Jan 31, 2022 | 7.5 | 37 | NO | YES |
CVE-2022-34121HIGH Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php. | Jul 27, 2022 | 7.5 | 35 | NO | YES |
CVE-2022-37191MEDIUM The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as | Sep 13, 2022 | 6.5 | 33 | NO | YES |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cuppacms.
Media articles that mention a CVE ID that affects a product developed by Cuppacms — matched by CVE ID, not by vendor name.