Elefant CMS is a modestly represented web content management system that, despite a narrow product scope, ranks among more prominent vendors in the vulnerability landscape. Vulnerabilities affecting the platform skew toward serious outcomes and recur through application-layer weakness classes including cross-site scripting, cross-site request forgery, code injection, and unrestricted file uploads—characteristic flaws of web frameworks where input handling and access controls are central to security posture. Defenders deploying this CMS should prioritize input validation and CSRF protections; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elefantcms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16975CRITICAL An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Nam | Sep 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-16974CRITICAL An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remov | Sep 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-15601CRITICAL apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism. | Aug 21, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-20064HIGH A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. T | Jun 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-20063HIGH A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File U | Jun 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-20062HIGH A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. | Jun 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-16387HIGH An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. | Sep 3, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-20058MEDIUM A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The ma | Jun 20, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-20061MEDIUM A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the | Jun 20, 2022 | 5.4 | 21 | NO | NO |
CVE-2017-20060MEDIUM A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part of the component Blog Post Handler. The manipulation leads to | Jun 20, 2022 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elefantcms.
Media articles that mention a CVE ID that affects a product developed by Elefantcms — matched by CVE ID, not by vendor name.