Ideacms is a content-management system whose disclosed vulnerabilities center on injection and access-control weaknesses, including SQL injection, cross-site scripting, command injection, and improper access control. These application-layer flaws are typical of web platforms handling user input and authentication; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ideacms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5569HIGH A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipul | Jun 4, 2025 | 8.8 | 35 | NO | YES |
CVE-2025-11331HIGH A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name Handler. Per | Oct 6, 2025 | 7.2 | 32 | NO | NO |
CVE-2025-14245CRITICAL A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulation of the argument params lead | Dec 8, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4291CRITICAL A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possibl | May 5, 2025 | 9.8 | 24 | NO | NO |
CVE-2018-16372MEDIUM The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued. | Sep 3, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ideacms.
Media articles that mention a CVE ID that affects a product developed by Ideacms — matched by CVE ID, not by vendor name.