Ilch is a content management system that, despite a narrow product footprint, sits within the top decile of represented vendors in the vulnerability landscape and draws recurring attention for web-application input-handling flaws. The vendor's disclosures concentrate on the Ilch CMS itself and cluster around application-layer weakness classes including cross-site scripting, cross-site request forgery, open-redirect, and unrestricted file upload—vulnerabilities characteristic of web frameworks where input validation and file-handling boundaries require consistent enforcement. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ilch over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17046HIGH Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page. | Sep 30, 2019 | 7.2 | 25 | NO | NO |
CVE-2014-1944MEDIUM Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/in | Mar 9, 2014 | 4.3 | 22 | NO | YES |
CVE-2021-27352MEDIUM An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login. | Mar 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2019-20524MEDIUM ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. | Mar 19, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-20523MEDIUM ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter. | Mar 19, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-20522MEDIUM ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter. | Mar 19, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-17045MEDIUM Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab. | Sep 30, 2019 | 4.8 | 18 | NO | NO |
CVE-2015-2083MEDIUM Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that add a value to a profile field | Feb 25, 2015 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ilch.
Media articles that mention a CVE ID that affects a product developed by Ilch — matched by CVE ID, not by vendor name.