Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pivotx

First CVE: Feb 4, 2011Active for: 15 yearsTotal CVEs: 16
45.0
VTI Score
High

Pivotx is a content-management and web-publishing platform whose vulnerability profile concentrates in a narrow product line, yet sits in the critical path for web-facing content delivery and administration. The recurring weakness classes—cross-site scripting, information disclosure, code injection, and input validation failures—are characteristic of web applications that handle user-generated content and dynamic page generation, and the vendor's disclosures tend toward public exploit availability. Defenders should treat updates to this platform as a priority, particularly for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pivotx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2011
15 years ago
Most Recent CVE
Sep 22, 2025
305 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-52367MEDIUM
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.
Sep 22, 20255.447NOYES
CVE-2017-8402HIGH
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.
May 31, 20178.827NONO
CVE-2017-7570HIGH
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the dupli
Apr 7, 20178.827NONO
CVE-2012-2274MEDIUM
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Aug 13, 20124.325NOYES
CVE-2011-1035HIGH
The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors.
Feb 19, 20117.525NONO
CVE-2011-0773MEDIUM
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image para
Feb 4, 20114.324NOYES
CVE-2011-0772MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the
Feb 4, 20114.324NOYES
CVE-2017-14958HIGH
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
Oct 2, 20177.223NONO
CVE-2017-9332MEDIUM
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
Jun 6, 20176.121NONO
CVE-2015-5458MEDIUM
Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter.
Jul 8, 20156.821NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
56%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network5 (31.3%)
Unknown11 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (31.3%)
High0 (0.0%)
Unknown11 (68.8%)
User Interaction
None3 (18.8%)
Unknown11 (68.8%)
Required2 (12.5%)
Privileges Required
Low3 (18.8%)
High1 (6.3%)
None1 (6.3%)
Unknown11 (68.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pivotx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pivotx's Products

View all 2 CNAs →

Top CWEs