Hashbrowncms operates a modestly represented content-management system product vulnerable to a durable pattern of input-handling and privilege-control weaknesses, particularly path-traversal conditions, OS command injection, and improper privilege management. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hashbrowncms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-6948CRITICAL A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repos | Jan 13, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-6949HIGH A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or othe | Jan 13, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-5840HIGH An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field. | Jan 6, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hashbrowncms.
Media articles that mention a CVE ID that affects a product developed by Hashbrowncms — matched by CVE ID, not by vendor name.