Frog CMS Project maintains a content-management system that, despite a narrow product footprint, has been a target for web-based attacks, with vulnerabilities frequently acquiring public exploit code. The recurring weakness classes—cross-site scripting, code injection, unsafe file uploads, cross-site request forgery, and information exposure—are characteristic of web application input handling and access-control challenges endemic to CMS platforms. Defenders running this system should prioritize patches for input-validation issues and restrict file-upload functionality; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frog Cms Project over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4912CRITICAL An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | Mar 22, 2018 | 9.8 | 44 | NO | YES |
CVE-2018-8908HIGH An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to tr | Mar 31, 2018 | 8.8 | 38 | NO | YES |
CVE-2021-26794CRITICAL Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file. | Sep 23, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-20448MEDIUM Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | Dec 25, 2018 | 5.4 | 29 | NO | YES |
CVE-2018-16447HIGH Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF. | Sep 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-10321MEDIUM Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | Apr 24, 2018 | 4.8 | 27 | NO | YES |
CVE-2024-46085HIGH FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename | Sep 17, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-46394HIGH FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add | Sep 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-46362HIGH FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory | Sep 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-42627HIGH FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3. | Aug 12, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frog Cms Project.
Media articles that mention a CVE ID that affects a product developed by Frog Cms Project — matched by CVE ID, not by vendor name.