Foxcms is a focused content-management system whose vulnerability profile, while concentrated in a single product, carries elevated weight due to a strong tendency toward critical-severity outcomes. The durable exposure recurs through application-layer input-handling and file-upload weakness classes including SQL injection, code injection, cross-site scripting, and unrestricted dangerous file uploads, which are characteristic of web-facing CMS platforms and reflect both parsing and access-control surface area. Defenders treating this vendor should prioritize patching and restrict direct internet exposure of CMS instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foxcms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-29306CRITICAL An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. | Mar 27, 2025 | 9.8 | 74 | NO | YES |
CVE-2025-50692CRITICAL FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html. | Aug 7, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10251CRITICAL A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the argument i | Sep 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55409HIGH FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code. | Aug 25, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-55422HIGH In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus. | Aug 27, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-55420HIGH A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the | Aug 21, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-25790CRITICAL An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file. | Feb 26, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-25789CRITICAL FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php. | Feb 26, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-5155HIGH A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article | May 25, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-56630HIGH FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file. | Sep 8, 2025 | 7.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foxcms.
Media articles that mention a CVE ID that affects a product developed by Foxcms — matched by CVE ID, not by vendor name.