Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pagekit

First CVE: Jan 25, 2017Active for: 9 yearsTotal CVEs: 14
52.2
VTI Score
TOP TARGET

Pagekit is a lightweight, open-source content management system whose vulnerability profile skews strongly toward critical-severity outcomes across its single product line. The recurring exposure centers on web-application input handling and file-upload validation, manifested through cross-site scripting, code injection, unsafe file uploads, authorization bypasses, and cross-site request forgery, reflecting common risks in CMS platforms that process and render user-supplied content. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching essential for instances exposed to untrusted networks; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pagekit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2017
9 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-38916CRITICAL
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
Sep 20, 20229.839NONO
CVE-2017-5594HIGH
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled.
Jan 25, 20177.539NOYES
CVE-2026-57518HIGH
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitr
Jun 26, 20268.835NONO
CVE-2025-67164CRITICAL
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP
Dec 17, 20259.934NONO
CVE-2021-44135CRITICAL
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
Apr 1, 20229.831NONO
CVE-2025-67165CRITICAL
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
Dec 17, 20259.830NONO
CVE-2018-11564MEDIUM
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the
Jun 2, 20184.829NOYES
CVE-2019-19013HIGH
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
Nov 22, 20198.827NONO
CVE-2023-41005HIGH
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
Aug 28, 20237.824NONO
CVE-2022-36573MEDIUM
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text bo
Aug 29, 20226.122NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
43%
29%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required8 (57.1%)
Privileges Required
Low3 (21.4%)
High1 (7.1%)
None10 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pagekit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pagekit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pagekit's Products

View all 2 CNAs →

Top CWEs