Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Impresscms

First CVE: Aug 4, 2008Active for: 18 yearsTotal CVEs: 21
45.3
VTI Score
High

Impresscms is a narrow, focused content management system whose vulnerability footprint, despite affecting a single product line, sits among the more prominent in its category and skews toward serious outcomes with a meaningful share reaching critical severity. The system's exposure centers on classic web-application weakness classes including cross-site scripting, SQL injection, path traversal, improper authentication, and type-confusion flaws that recur across its codebase and frequently acquire public exploit code. These input-handling and access-control vulnerabilities reflect the complexity inherent to a broadly feature-rich CMS that processes user-supplied content and manages privileged operations. Defenders should treat Impresscms releases as requiring timely review, particularly when user input handling or authentication changes are involved; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Impresscms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 4, 2008
17 years ago
Most Recent CVE
Apr 12, 2026
103 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-26599CRITICAL
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
Mar 28, 20229.863NOYES
CVE-2022-26986HIGH
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive informatio
Apr 5, 20227.236NOYES
CVE-2022-50912CRITICAL
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload
Jan 13, 20269.834NONO
CVE-2021-26600CRITICAL
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
Mar 28, 20229.834NONO
CVE-2021-26598MEDIUM
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
Mar 28, 20225.334NOYES
CVE-2022-24977CRITICAL
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor proc
Feb 14, 20229.834NONO
CVE-2021-26601HIGH
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
Mar 28, 20228.128NONO
CVE-2019-25703HIGH
ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid'
Apr 12, 20268.827NONO
CVE-2014-1836MEDIUM
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathna
Jul 1, 20156.426NOYES
CVE-2008-3453HIGH
Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."
Aug 4, 200810.025NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
57%
24%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (57.1%)
Unknown9 (42.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (57.1%)
High0 (0.0%)
Unknown9 (42.9%)
User Interaction
None8 (38.1%)
Unknown9 (42.9%)
Required4 (19.0%)
Privileges Required
Low3 (14.3%)
High3 (14.3%)
None6 (28.6%)
Unknown9 (42.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.5% of CVEs· 96th percentile
ExploitDB
3 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Impresscms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Impresscms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Impresscms's Products

View all 2 CNAs →

Top CWEs