Luocms Project maintains a narrowly scoped content-management system whose vulnerability profile skews strongly toward critical-severity outcomes, with recurring exposure in SQL injection, cross-site scripting, and authorization weaknesses typical of web application input handling and access control. Despite its niche footprint, the product's role in web-facing deployment and the severity tendency of its disclosures warrant monitoring by defenders managing affected installations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Luocms Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24607CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | Mar 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-24602CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | Mar 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-24600CRITICAL Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | Mar 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24609CRITICAL Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-24606CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-24605CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-24604CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-24603CRITICAL Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-24601HIGH Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements. | Mar 10, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24608MEDIUM Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | Mar 10, 2022 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luocms Project.
Media articles that mention a CVE ID that affects a product developed by Luocms Project — matched by CVE ID, not by vendor name.