Pagekit is a lightweight, open-source content management system whose vulnerability profile skews strongly toward critical-severity outcomes across its single product line. The recurring exposure centers on web-application input handling and file-upload validation, manifested through cross-site scripting, code injection, unsafe file uploads, authorization bypasses, and cross-site request forgery, reflecting common risks in CMS platforms that process and render user-supplied content. Vulnerabilities affecting this vendor frequently acquire public exploit code, making timely patching essential for instances exposed to untrusted networks; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pagekit over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38916CRITICAL A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files | Sep 20, 2022 | 9.8 | 39 | NO | NO |
CVE-2017-5594HIGH An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. | Jan 25, 2017 | 7.5 | 39 | NO | YES |
CVE-2026-57518HIGH Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitr | Jun 26, 2026 | 8.8 | 35 | NO | NO |
CVE-2025-67164CRITICAL An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP | Dec 17, 2025 | 9.9 | 34 | NO | NO |
CVE-2021-44135CRITICAL pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing. | Apr 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-67165CRITICAL An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. | Dec 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2018-11564MEDIUM Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the | Jun 2, 2018 | 4.8 | 29 | NO | YES |
CVE-2019-19013HIGH A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request. | Nov 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2023-41005HIGH An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php | Aug 28, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-36573MEDIUM A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text bo | Aug 29, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pagekit.
Media articles that mention a CVE ID that affects a product developed by Pagekit — matched by CVE ID, not by vendor name.