Impresscms is a narrow, focused content management system whose vulnerability footprint, despite affecting a single product line, sits among the more prominent in its category and skews toward serious outcomes with a meaningful share reaching critical severity. The system's exposure centers on classic web-application weakness classes including cross-site scripting, SQL injection, path traversal, improper authentication, and type-confusion flaws that recur across its codebase and frequently acquire public exploit code. These input-handling and access-control vulnerabilities reflect the complexity inherent to a broadly feature-rich CMS that processes user-supplied content and manages privileged operations. Defenders should treat Impresscms releases as requiring timely review, particularly when user input handling or authentication changes are involved; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Impresscms over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26599CRITICAL ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | Mar 28, 2022 | 9.8 | 63 | NO | YES |
CVE-2022-26986HIGH SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive informatio | Apr 5, 2022 | 7.2 | 36 | NO | YES |
CVE-2022-50912CRITICAL ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload | Jan 13, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-26600CRITICAL ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). | Mar 28, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-26598MEDIUM ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token). | Mar 28, 2022 | 5.3 | 34 | NO | YES |
CVE-2022-24977CRITICAL ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor proc | Feb 14, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-26601HIGH ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. | Mar 28, 2022 | 8.1 | 28 | NO | NO |
CVE-2019-25703HIGH ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' | Apr 12, 2026 | 8.8 | 27 | NO | NO |
CVE-2014-1836MEDIUM Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathna | Jul 1, 2015 | 6.4 | 26 | NO | YES |
CVE-2008-3453HIGH Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files." | Aug 4, 2008 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Impresscms.
Media articles that mention a CVE ID that affects a product developed by Impresscms — matched by CVE ID, not by vendor name.