Pescms maintains a focused team collaboration and project-management platform that, despite its narrow product scope, skews toward serious vulnerability outcomes with a meaningful share reaching critical severity and a notable tendency to acquire public exploit code. The exposure recurs through a consistent set of web-application layer weaknesses—cross-site request forgery, cross-site scripting, and unrestricted file uploads—that are characteristic of input-handling and session-management gaps in collaborative software. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pescms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16370CRITICAL In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive. | Sep 3, 2018 | 9.8 | 30 | NO | NO |
CVE-2020-28092MEDIUM PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task& | Nov 17, 2020 | 6.1 | 28 | NO | YES |
CVE-2021-31679MEDIUM An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers. | Jul 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-31678MEDIUM An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company. | Jul 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-31677MEDIUM An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords. | Jul 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-31676MEDIUM A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruction. | Jul 6, 2022 | 6.1 | 22 | NO | NO |
CVE-2018-16371MEDIUM PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, | Sep 3, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pescms.
Media articles that mention a CVE ID that affects a product developed by Pescms — matched by CVE ID, not by vendor name.