Idreamsoft maintains a narrowly scoped portfolio centered on the iCMS content-management system, which despite modest product breadth achieves notable prominence in web-application vulnerability tracking. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur consistently across a characteristic set of web-application weaknesses: cross-site request forgery, path traversal, cross-site scripting, SQL injection, and code injection. These classes reflect the input-handling and authorization demands of a CMS platform exposed to user-supplied content and administrative functionality. Defenders deploying or maintaining iCMS instances should prioritize patch cycles and enforce strict input validation and access controls; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idreamsoft over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44978CRITICAL iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. | Feb 4, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-41496CRITICAL iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-19142CRITICAL iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. | Dec 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-17552CRITICAL An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimens | Oct 14, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-7160CRITICAL idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP fil | Jan 29, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-19527CRITICAL iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. | Dec 10, 2020 | 9.8 | 28 | NO | NO |
CVE-2019-7234CRITICAL An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with th | Jan 30, 2019 | 9.1 | 28 | NO | NO |
CVE-2018-16365HIGH An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF. | Sep 2, 2018 | 8.8 | 28 | NO | NO |
CVE-2023-39806CRITICAL iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | Aug 10, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-39805CRITICAL iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. | Aug 10, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idreamsoft.
Media articles that mention a CVE ID that affects a product developed by Idreamsoft — matched by CVE ID, not by vendor name.