Flexdotnetcms Project develops a content-management system whose vulnerability profile centers on file-handling weaknesses, specifically path-traversal and unrestricted file-upload flaws that expose the application to directory-escape and malicious-file-execution risks. This represents a compact vendor profile focused on a single product; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flexdotnetcms Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27386HIGH An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload ma | Nov 12, 2020 | 8.8 | 76 | NO | YES |
CVE-2020-27385HIGH Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files ou | Nov 12, 2020 | 8.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flexdotnetcms Project.
Media articles that mention a CVE ID that affects a product developed by Flexdotnetcms Project — matched by CVE ID, not by vendor name.