Gougucms maintains a compact portfolio centered on its content-management and office-automation products, with a durable vulnerability signal anchored in application-layer input-handling issues, particularly cross-site scripting flaws and exception-handling weaknesses. Treat this as a focused vendor profile; current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gougucms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46393HIGH gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet. | Oct 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-3035MEDIUM A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of | Jun 1, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-46394MEDIUM A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted p | Oct 27, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gougucms.
Media articles that mention a CVE ID that affects a product developed by Gougucms — matched by CVE ID, not by vendor name.