Lulucms is a content-management system with a narrowly scoped product footprint, and its vulnerability exposure centers on the core Lulu CMS product. The durable signal is driven by file-upload handling weaknesses, specifically unrestricted upload of files with dangerous types, a class of flaw that commonly arises in web-based content platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lulucms over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18771HIGH An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory | Oct 29, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lulucms.
Media articles that mention a CVE ID that affects a product developed by Lulucms — matched by CVE ID, not by vendor name.