Jupiter CMS is a modestly represented content-management platform whose vulnerability profile is distinguished by a strong tendency toward public exploit availability, reflecting the appeal of web-facing administrative interfaces to attackers. The recurring exposure centers on the single product and clusters around code-injection weaknesses and related control-flow issues that are characteristic of template engines and dynamic content systems. Defenders should prioritize patches for this platform and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jupiter Cms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4428CRITICAL PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disp | Aug 29, 2006 | 9.8 | 35 | NO | YES |
CVE-2007-0972HIGH Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an imag | Feb 16, 2007 | 7.5 | 31 | NO | YES |
CVE-2007-0971HIGH Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, w | Feb 16, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-0987HIGH Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname | Feb 16, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-4876HIGH Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername | Sep 19, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4875MEDIUM Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extens | Sep 19, 2006 | 5.0 | 25 | NO | YES |
CVE-2007-0986MEDIUM PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in | Feb 16, 2007 | 5.1 | 23 | NO | YES |
CVE-2006-4874MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[A | Sep 19, 2006 | 4.3 | 22 | NO | YES |
CVE-2006-1679MEDIUM Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the layout parameter to index | Apr 11, 2006 | 4.3 | 22 | NO | YES |
CVE-2006-1223MEDIUM Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the ima | Mar 14, 2006 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jupiter Cms.
Media articles that mention a CVE ID that affects a product developed by Jupiter Cms — matched by CVE ID, not by vendor name.