Kasseler CMS is a niche content management system that, despite modest disclosure volume, holds a position more prominent than many similarly scoped products in the vulnerability landscape. The vendor's exposure is concentrated in its single CMS product, with no durable pattern of particular weakness classes emerging from the available disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kasseler Cms over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3727HIGH SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this | Mar 13, 2014 | 7.5 | 29 | NO | YES |
CVE-2008-4356HIGH Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View act | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2013-3729MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that co | Mar 13, 2014 | 6.8 | 26 | NO | YES |
CVE-2009-2229MEDIUM Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a downloa | Jun 26, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-3087MEDIUM Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to t | Jul 9, 2008 | 5.0 | 23 | NO | YES |
CVE-2009-4822MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) | Apr 27, 2010 | 4.3 | 22 | NO | YES |
CVE-2009-2228MEDIUM Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url parameter in a redirect action. | Jun 26, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-3088MEDIUM Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid paramet | Jul 9, 2008 | 4.3 | 21 | NO | YES |
Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HT | Mar 13, 2014 | 3.5 | 20 | NO | YES |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kasseler Cms.
Media articles that mention a CVE ID that affects a product developed by Kasseler Cms — matched by CVE ID, not by vendor name.