Itcms develops a focused suite of content management systems, primarily Itcms and Vigile CMS, whose vulnerability footprint centers on application-layer input-handling issues. The recurring exposure involves code injection and cross-site scripting weaknesses characteristic of web-based CMS platforms where user input flows through templating and rendering logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itcms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2192HIGH Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box/MiniChat/data/shouts.php via | May 14, 2008 | 10.0 | 36 | NO | YES |
CVE-2007-4115MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.ph | Jul 31, 2007 | 4.3 | 25 | NO | YES |
CVE-2007-5052MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbitrary web script or HTML via a request to the wiki module wi | Sep 24, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itcms.
Media articles that mention a CVE ID that affects a product developed by Itcms — matched by CVE ID, not by vendor name.