Jellycms is a niche content management system with a compact product footprint, and its observed vulnerability landscape centers on file-upload handling. The durable pattern reflects the product's need to accept and manage user-supplied content, with recurring exposure around unrestricted file-upload mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jellycms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26630HIGH Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php. | Apr 5, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jellycms.
Media articles that mention a CVE ID that affects a product developed by Jellycms — matched by CVE ID, not by vendor name.