Foru CMS Project maintains a single content-management system that, despite modest disclosure volume, exhibits a narrow but critical weakness profile centered on input-handling and code-generation flaws. The recurring vulnerability classes—SQL injection, file-path manipulation, external resource references, and code injection—reflect the application-layer risks inherent to a web-based CMS handling user input and dynamic content generation, and vulnerabilities affecting this product skew strongly toward critical-severity outcomes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foru Cms Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5221CRITICAL A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of the argument db_name leads to co | Sep 27, 2023 | 9.8 | 28 | NO | NO |
CVE-2024-0426CRITICAL A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. This issue affects some unknown processing of the file admin/cms_template.php. The m | Jan 11, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-0729CRITICAL A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. Affected by this issue is some unknown functionality of the file cms_admin.php. The | Jan 19, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-0728CRITICAL A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an unknown functionality of the file channel.php. The manipulati | Jan 19, 2024 | 9.8 | 24 | NO | NO |
CVE-2024-0425HIGH A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipul | Jan 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-5259MEDIUM A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /admin/cms_admin.php. The manipulation of the argument del lead | Sep 29, 2023 | 4.9 | 15 | NO | NO |
CVE-2022-3943MEDIUM A vulnerability was found in ForU CMS. It has been classified as problematic. Affected is an unknown function of the file cms_chip.php. The manipulation of the argument name leads | Nov 11, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foru Cms Project.
Media articles that mention a CVE ID that affects a product developed by Foru Cms Project — matched by CVE ID, not by vendor name.