Gleezcms is a lightweight web content-management system whose vulnerability profile concentrates around its core product and reflects recurrent web-application input-handling and request-validation issues, including cross-site scripting, cross-site request forgery, and server-side request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gleezcms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15845HIGH There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | Aug 25, 2018 | 8.8 | 38 | NO | YES |
CVE-2021-27312CRITICAL Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/re | Apr 3, 2024 | 9.4 | 24 | NO | NO |
CVE-2018-16347MEDIUM An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize. | Sep 2, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-7035MEDIUM Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in St | Apr 5, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gleezcms.
Media articles that mention a CVE ID that affects a product developed by Gleezcms — matched by CVE ID, not by vendor name.