Engineercms Project maintains a focused web-based content-management system where the vulnerability exposure concentrates on application-layer input-handling defects, specifically SQL injection and cross-site scripting. These weakness classes reflect the parsing and output-encoding demands of web-facing form processing and database interaction in CMS platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Engineercms Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-44830CRITICAL EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface. | May 12, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-44831CRITICAL EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface. | May 13, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-36605MEDIUM engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be | Jul 30, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Engineercms Project.
Media articles that mention a CVE ID that affects a product developed by Engineercms Project — matched by CVE ID, not by vendor name.