Ed01 CMS Project maintains a single, niche content-management system that has accumulated a modest vulnerability footprint relative to its deployment scope. The underlying weakness patterns have not yet been characterized into durable classes, suggesting either diverse flaw types or limited historical analysis; defenders should monitor this vendor's advisories and patch timeline. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ed01 Cms Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28524CRITICAL ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | Apr 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-18262CRITICAL ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | Nov 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-18261CRITICAL An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. | Nov 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-28525HIGH ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | Apr 26, 2022 | 8.8 | 22 | NO | NO |
CVE-2020-18259MEDIUM ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary | Nov 3, 2021 | 6.1 | 20 | NO | NO |
CVE-2024-30890MEDIUM Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. | Apr 25, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ed01 Cms Project.
Media articles that mention a CVE ID that affects a product developed by Ed01 Cms Project — matched by CVE ID, not by vendor name.