Ecisp develops a focused content-management system product line, primarily the ESPCMS family, that serves as a web-publishing platform with a relatively small but persistent vulnerability footprint. The system's exposure recurs through classic web-application weaknesses—SQL injection, cross-site scripting, and code injection—that reflect the challenges of user-input handling and templating in CMS platforms, and a meaningful share of the vendor's disclosures reach critical severity. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecisp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44088CRITICAL ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | Nov 10, 2022 | 9.8 | 36 | NO | NO |
CVE-2022-44087CRITICAL ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. | Nov 10, 2022 | 9.8 | 34 | NO | NO |
CVE-2022-44089CRITICAL ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. | Nov 10, 2022 | 9.8 | 33 | NO | NO |
CVE-2020-18913HIGH EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers | Aug 24, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-33085HIGH ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates. | Jun 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-23007HIGH An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added. | Feb 17, 2023 | 7.2 | 23 | NO | NO |
CVE-2020-18404MEDIUM An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter. | Jun 27, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecisp.
Media articles that mention a CVE ID that affects a product developed by Ecisp — matched by CVE ID, not by vendor name.