Nucleuscms is a content-management system whose vulnerability profile concentrates in a single core product and skews toward serious outcomes, with a meaningful share reaching critical severity and a tendency toward public exploit availability. The recurring exposure spans classic web-application weaknesses including cross-site scripting, SQL injection, code injection, unrestricted file uploads, and information disclosure, reflecting the input-handling and code-execution risks inherent to dynamic content platforms. Defenders should treat Nucleuscms installations as requiring close monitoring for available patches; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nucleuscms over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21474CRITICAL File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2010-5041HIGH SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action | Nov 2, 2011 | 7.5 | 30 | NO | YES |
CVE-2010-5040MEDIUM PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL | Nov 2, 2011 | 6.8 | 30 | NO | YES |
CVE-2021-37770HIGH Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Ht | Jun 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2018-16636MEDIUM Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | Dec 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2008-0497MEDIUM Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted whe | Jan 30, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-5429MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter. | Oct 12, 2007 | 4.3 | 21 | NO | YES |
CVE-2006-6920MEDIUM Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN | Jan 11, 2007 | 6.8 | 18 | NO | NO |
CVE-2011-3760MEDIUM Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated b | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2008-4446MEDIUM Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Oct 6, 2008 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nucleuscms.
Media articles that mention a CVE ID that affects a product developed by Nucleuscms — matched by CVE ID, not by vendor name.