Neos maintains a focused content-management platform and related form components, with a vulnerability profile centered on web-application input-handling deficiencies such as cross-site scripting and improper input validation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neos over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32697MEDIUM neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validator | Jun 21, 2021 | 5.3 | 19 | NO | NO |
CVE-2023-37611MEDIUM Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media comp | Sep 18, 2023 | 5.4 | 17 | NO | NO |
CVE-2022-30429MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, th | Jun 2, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neos.
Media articles that mention a CVE ID that affects a product developed by Neos — matched by CVE ID, not by vendor name.