Hongcms Project maintains a web content management system that, despite a focused product portfolio, operates across a distributed and modestly represented attack surface. The vulnerability profile centers on a single product, Hongcms, and recurs through weaknesses inherent to web application input handling and access control: cross-site scripting, path traversal, SQL injection, and cross-site request forgery, reflecting the parsing and state-management demands of a server-side CMS platform. The weakness classes and volume indicate exposure patterns consistent with applications that process user input across templating and database layers without sufficient sanitization or validation boundaries. Defenders deploying this platform should prioritize input validation and output encoding controls, and track the vendor's advisories for remediation in their CMS instances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hongcms Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12912HIGH An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&table | Jun 27, 2018 | 7.2 | 34 | NO | YES |
CVE-2020-21252HIGH Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter. | Jun 20, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-28523HIGH HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | Apr 26, 2022 | 8.1 | 26 | NO | NO |
CVE-2018-10265HIGH An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI. | Apr 22, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-32412HIGH An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell. | Jul 1, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-32411HIGH An issue in the languages config file of HongCMS v3.0 allows attackers to getshell. | Jul 1, 2022 | 7.2 | 24 | NO | NO |
CVE-2020-18178CRITICAL Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax. | May 18, 2021 | 9.8 | 24 | NO | NO |
CVE-2018-16774HIGH HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete. | Sep 10, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-13021HIGH An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI. | Jun 29, 2018 | 7.2 | 24 | NO | NO |
CVE-2020-21431MEDIUM HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit. | Oct 4, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hongcms Project.
Media articles that mention a CVE ID that affects a product developed by Hongcms Project — matched by CVE ID, not by vendor name.