Ftcms is a modestly represented content-management system with a durable signal in a narrow product line and a skew toward serious-severity outcomes across its disclosures. Vulnerabilities affecting the vendor concentrate in path-traversal, cross-site scripting, code-injection, and cross-site request forgery flaws, which are characteristic of web application input handling and code generation boundaries. Live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ftcms over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30063CRITICAL ftcms <=2.1 was discovered to be vulnerable to code execution attacks . | May 11, 2022 | 9.8 | 39 | NO | NO |
CVE-2022-37730HIGH In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or vis | Sep 7, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-37731MEDIUM ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing the user / administrator to trigger malicious code when acce | Sep 7, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-30062MEDIUM ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php | May 11, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-30060HIGH ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Write via admin/controllers/tp.php | May 11, 2022 | 8.8 | 22 | NO | NO |
CVE-2025-2132HIGH A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The man | Mar 9, 2025 | 7.2 | 21 | NO | NO |
CVE-2022-30061MEDIUM ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp. | May 11, 2022 | 6.5 | 18 | NO | NO |
CVE-2025-2133MEDIUM A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/index.php/news/edit. The manipulatio | Mar 10, 2025 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ftcms.
Media articles that mention a CVE ID that affects a product developed by Ftcms — matched by CVE ID, not by vendor name.