Evo develops Evolution CMS, a content management platform where the disclosed vulnerabilities center on web-application input handling, specifically cross-site scripting weaknesses arising from improper neutralization during page generation. This represents a compact vendor profile focused on a single product line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23238MEDIUM Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature. | Jul 26, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-43341MEDIUM Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter. | Oct 19, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-43340MEDIUM Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cms | Oct 19, 2023 | 5.2 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evo.
Media articles that mention a CVE ID that affects a product developed by Evo — matched by CVE ID, not by vendor name.