Flamecms Project maintains a lightweight content management system product that presents a focused but strategically important attack surface in web application deployments. The durable vulnerability signal centers on SQL injection weaknesses in the core product, reflecting common input-handling challenges in database-driven CMS platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flamecms Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16309CRITICAL FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | Sep 14, 2019 | 9.8 | 32 | NO | NO |
CVE-2020-20797CRITICAL FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | Sep 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-20796CRITICAL FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | Sep 30, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flamecms Project.
Media articles that mention a CVE ID that affects a product developed by Flamecms Project — matched by CVE ID, not by vendor name.