Frogcms Project maintains a focused content management system that, despite a narrow product portfolio, has accumulated vulnerabilities across a meaningful volume of disclosures. The exposure concentrates in the core Frogcms product and recurs through application-layer weakness classes—cross-site request forgery, cross-site scripting, path traversal, and unrestricted file uploads—that are characteristic of web-application input handling and access control. These classes reflect the parsing and trust-boundary challenges inherent to extensible CMS platforms where user-controllable content flows through templating and file-management subsystems. Defenders running this CMS should prioritize input validation and upload restrictions alongside regular patching; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frogcms Project over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4912CRITICAL An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | Mar 22, 2018 | 9.8 | 44 | NO | YES |
CVE-2018-8908HIGH An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to tr | Mar 31, 2018 | 8.8 | 38 | NO | YES |
CVE-2021-26794CRITICAL Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file. | Sep 23, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-20448MEDIUM Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | Dec 25, 2018 | 5.4 | 29 | NO | YES |
CVE-2018-16447HIGH Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF. | Sep 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-10321MEDIUM Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | Apr 24, 2018 | 4.8 | 27 | NO | YES |
CVE-2024-46085HIGH FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename | Sep 17, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-46394HIGH FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add | Sep 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-46362HIGH FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory | Sep 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-42627HIGH FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3. | Aug 12, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frogcms Project.
Media articles that mention a CVE ID that affects a product developed by Frogcms Project — matched by CVE ID, not by vendor name.