Easycms

Vendor:

First CVE: Feb 1, 2006 · Active for 20 years

16
Total CVEs
Bottom 1%
2.7
Avg CVEs / Year
Bottom 1%
7.0
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Easycms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2006
20 years ago
Most Recent CVE
Mar 8, 2026
138 days ago

CVE Severity & Scoring

Easycms16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (81.3%)
Unknown3 (18.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (81.3%)
High0 (0.0%)
Unknown3 (18.8%)
User Interaction
None4 (25.0%)
Unknown3 (18.8%)
Required9 (56.3%)
Privileges Required
Low3 (18.8%)
High1 (6.3%)
None9 (56.3%)
Unknown3 (18.8%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sq
Jan 18, 20269.834NONO
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQ
Feb 16, 20229.830NONO
A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handl
Mar 8, 20268.827NONO
A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. T
Mar 8, 20268.827NONO
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
Jan 15, 20198.827NONO
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/clos
Sep 2, 20188.827NONO
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post
Feb 1, 20218.826NONO
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
Sep 9, 20186.121NONO
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
Jun 29, 20186.521NONO
App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.
Sep 17, 20186.120NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Easycms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.629.30.9%00
1.547.10.6%00
1.416.10.7%00
1.336.00.6%00
0.1.214.61.2%00