Dilicms is a niche content management system with a focused vulnerability footprint concentrated in its single core product. The recurring weakness classes—cross-site scripting and cross-site request forgery—reflect the web application input-handling and state-management challenges typical of CMS platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dilicms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19291MEDIUM An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI. | Nov 15, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-18210MEDIUM XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. | Oct 10, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-18209MEDIUM XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter. | Oct 10, 2018 | 6.1 | 21 | NO | NO |
CVE-2019-8439MEDIUM An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain. | Mar 7, 2019 | 5.4 | 19 | NO | NO |
CVE-2019-8440MEDIUM An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_lo | Mar 7, 2019 | 4.8 | 18 | NO | NO |
CVE-2018-10430MEDIUM An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php. | Apr 26, 2018 | 4.8 | 17 | NO | NO |
CVE-2019-8438MEDIUM An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name. | Mar 7, 2019 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dilicms.
Media articles that mention a CVE ID that affects a product developed by Dilicms — matched by CVE ID, not by vendor name.