Onefilecms is a niche content-management system with a narrow product portfolio whose vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure centers on the core Onefilecms product through weakness classes including code injection, sensitive-information disclosure, brute-force authentication gaps, and improper permission assignment—attack surfaces typical of web-based administrative interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onefilecms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12993CRITICAL onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields. | Jun 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-12995HIGH onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen. | Jun 29, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12994HIGH onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen. | Jun 29, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-13123CRITICAL onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /et | Jul 3, 2018 | 9.8 | 26 | NO | NO |
CVE-2018-13122MEDIUM onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edi | Jul 3, 2018 | 6.5 | 19 | NO | NO |
CVE-2019-8408MEDIUM OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice. | Feb 17, 2019 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onefilecms.
Media articles that mention a CVE ID that affects a product developed by Onefilecms — matched by CVE ID, not by vendor name.