Eleanor CMS is a modestly scoped content management system with a narrow product footprint relative to mainstream web platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eleanor Cms over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9180MEDIUM Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING. | Dec 2, 2014 | 5.0 | 24 | NO | YES |
CVE-2018-18717MEDIUM An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI. | Oct 29, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eleanor Cms.
Media articles that mention a CVE ID that affects a product developed by Eleanor Cms — matched by CVE ID, not by vendor name.