Gleeztech maintains a content-management system product with a narrow but notable footprint, where vulnerabilities cluster around web-application input and access-control weaknesses including cross-site scripting, cross-site request forgery, authorization bypass, and brute-force protection gaps. These patterns reflect the challenges of securing user-facing CMS functionality against injection and session-handling attacks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gleeztech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13340HIGH Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request. | Jul 5, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-16703MEDIUM A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perfo | Sep 7, 2018 | 5.3 | 20 | NO | NO |
CVE-2018-1999021MEDIUM Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page edi | Jul 23, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-16704MEDIUM An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of ot | Sep 7, 2018 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gleeztech.
Media articles that mention a CVE ID that affects a product developed by Gleeztech — matched by CVE ID, not by vendor name.