Modstart is a niche content-management and website-building platform with a modest security footprint centered on its Modstart CMS product. The recurring vulnerability signal reflects application-layer input-handling weaknesses, specifically command-injection and open-redirect flaws that are common in web platforms where user input reaches system execution or redirect logic. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modstart over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55824MEDIUM ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commands to obtain sensitive data on the server. | Sep 2, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-46331HIGH ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an a | Sep 27, 2024 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modstart.
Media articles that mention a CVE ID that affects a product developed by Modstart — matched by CVE ID, not by vendor name.