Flusity is a narrowly scoped vendor with a single, focused product line that nevertheless commands prominence in the vulnerability landscape, accruing a substantial number of disclosures relative to its product footprint. Vulnerabilities affecting Flusity skew strongly toward serious and critical severity outcomes, concentrated in application-layer weaknesses endemic to web platforms: cross-site request forgery, cross-site scripting, code injection, unrestricted file upload, and improper access control. These patterns reflect the exposure surface inherent to web-facing applications and the recurrent risks of insufficient input sanitization and request validation. Defenders should prioritize Flusity disclosures despite the narrow product scope, since the severity tendency and persistent weakness classes indicate a need for careful remediation. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flusity over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31666CRITICAL An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component. | Apr 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-32418CRITICAL An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. | Apr 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-25502CRITICAL Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component. | Feb 15, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-25419HIGH flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php. | Feb 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-25418HIGH flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php. | Feb 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-25417HIGH flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php. | Feb 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24469HIGH Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php. | Feb 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24468HIGH Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php. | Feb 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24470HIGH Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component. | Feb 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24524HIGH Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component. | Feb 2, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flusity.
Media articles that mention a CVE ID that affects a product developed by Flusity — matched by CVE ID, not by vendor name.