Idccms is a content management system with a moderate vulnerability footprint concentrated in a single, narrowly scoped product. The recurring weakness classes—cross-site request forgery, cross-site scripting, code injection, and input-validation gaps—are characteristic of web application architectures where user-controlled data flows into rendering, execution, or state-modification contexts without sufficient sanitization or isolation. Defenders should prioritize input-handling and output-encoding review when assessing this vendor's updates, particularly in contexts where the CMS is internet-facing or processes untrusted content. Current exploitation activity, severity breakdowns, and detailed exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idccms over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11587MEDIUM A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of t | Nov 21, 2024 | 6.1 | 28 | NO | YES |
CVE-2024-40331HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup | Jul 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-40332HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40334HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3 | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40333HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2 | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40329HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39023HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39022HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39158HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet. | Jun 27, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39154HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN. | Jun 27, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idccms.
Media articles that mention a CVE ID that affects a product developed by Idccms — matched by CVE ID, not by vendor name.