Ferretcms Project maintains a content management system whose vulnerability profile centers on application-layer web security issues, particularly cross-site request forgery, improper input validation, cross-site scripting, and SQL injection. These weaknesses reflect the parsing and user-input handling demands typical of web-based CMS platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ferretcms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1372HIGH SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php. | Jan 27, 2015 | 7.5 | 31 | NO | YES |
CVE-2015-1371HIGH Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then access | Jan 27, 2015 | 7.5 | 31 | NO | YES |
CVE-2015-1374MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests | Jan 27, 2015 | 6.8 | 26 | NO | YES |
CVE-2015-1373MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter | Jan 27, 2015 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ferretcms Project.
Media articles that mention a CVE ID that affects a product developed by Ferretcms Project — matched by CVE ID, not by vendor name.