Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Frog Cms Project

First CVE: Mar 22, 2018Active for: 8 yearsTotal CVEs: 42
44.9
VTI Score
High

Frog CMS Project maintains a content-management system that, despite a narrow product footprint, has been a target for web-based attacks, with vulnerabilities frequently acquiring public exploit code. The recurring weakness classes—cross-site scripting, code injection, unsafe file uploads, cross-site request forgery, and information exposure—are characteristic of web application input handling and access-control challenges endemic to CMS platforms. Defenders running this system should prioritize patches for input-validation issues and restrict file-upload functionality; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 95% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Frog Cms Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2018
8 years ago
Most Recent CVE
Sep 19, 2024
674 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-4912CRITICAL
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
Mar 22, 20189.844NOYES
CVE-2018-8908HIGH
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to tr
Mar 31, 20188.838NOYES
CVE-2021-26794CRITICAL
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
Sep 23, 20219.829NONO
CVE-2018-20448MEDIUM
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
Dec 25, 20185.429NOYES
CVE-2018-16447HIGH
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
Sep 4, 20188.827NONO
CVE-2018-10321MEDIUM
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
Apr 24, 20184.827NOYES
CVE-2024-46085HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
Sep 17, 20248.825NONO
CVE-2024-46394HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
Sep 19, 20248.824NONO
CVE-2024-46362HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
Sep 17, 20248.824NONO
CVE-2024-42627HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.
Aug 12, 20248.824NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
45%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (21.4%)
Unknown0 (0.0%)
Required33 (78.6%)
Privileges Required
Low5 (11.9%)
High16 (38.1%)
None21 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
9.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Frog Cms Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Frog Cms Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Frog Cms Project's Products

View all 2 CNAs →

Top CWEs