Idccms Project maintains a niche content management system where the observed vulnerability exposure centers on a single product and recurs through cross-site request forgery weaknesses. This narrow footprint reflects the application-layer input-handling and session-state challenges typical of web-based CMS platforms. Current severity, exploitation status, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idccms Project over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11587MEDIUM A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of t | Nov 21, 2024 | 6.1 | 28 | NO | YES |
CVE-2024-40331HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup | Jul 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-40332HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40334HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3 | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40333HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2 | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-40329HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup | Jul 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39023HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39022HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal | Jul 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39158HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet. | Jun 27, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39154HIGH idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN. | Jun 27, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idccms Project.
Media articles that mention a CVE ID that affects a product developed by Idccms Project — matched by CVE ID, not by vendor name.