Lovecms maintains a narrowly scoped portfolio centered on a content management system and associated forum product, with a vulnerability profile anchored in code-injection, path-traversal, and cross-site-scripting weaknesses that are characteristic of web-application input handling and template-processing logic. Despite the focused product scope, the vendor's disclosures frequently acquire public exploit tooling, making timely patching and input validation hardening operationally important for deployments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lovecms over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5308HIGH The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator passwor | Dec 2, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-7062MEDIUM Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute arbitrary code by uploading a fi | Aug 25, 2009 | 6.8 | 29 | NO | YES |
CVE-2008-3509HIGH LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the | Aug 7, 2008 | 7.5 | 29 | NO | YES |
CVE-2007-1148HIGH PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. | Mar 2, 2007 | 7.5 | 29 | NO | YES |
CVE-2007-1149MEDIUM Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) | Mar 2, 2007 | 5.0 | 29 | NO | YES |
CVE-2008-5794MEDIUM Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter. | Dec 31, 2008 | 5.0 | 23 | NO | YES |
CVE-2007-1151MEDIUM Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related t | Mar 2, 2007 | 4.3 | 21 | NO | YES |
Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/. | Mar 2, 2007 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lovecms.
Media articles that mention a CVE ID that affects a product developed by Lovecms — matched by CVE ID, not by vendor name.