Pivotx is a content-management and web-publishing platform whose vulnerability profile concentrates in a narrow product line, yet sits in the critical path for web-facing content delivery and administration. The recurring weakness classes—cross-site scripting, information disclosure, code injection, and input validation failures—are characteristic of web applications that handle user-generated content and dynamic page generation, and the vendor's disclosures tend toward public exploit availability. Defenders should treat updates to this platform as a priority, particularly for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pivotx over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52367MEDIUM Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field. | Sep 22, 2025 | 5.4 | 47 | NO | YES |
CVE-2017-8402HIGH PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file. | May 31, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-7570HIGH PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the dupli | Apr 7, 2017 | 8.8 | 27 | NO | NO |
CVE-2012-2274MEDIUM Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter. | Aug 13, 2012 | 4.3 | 25 | NO | YES |
CVE-2011-1035HIGH The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors. | Feb 19, 2011 | 7.5 | 25 | NO | NO |
CVE-2011-0773MEDIUM Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image para | Feb 4, 2011 | 4.3 | 24 | NO | YES |
CVE-2011-0772MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the | Feb 4, 2011 | 4.3 | 24 | NO | YES |
CVE-2017-14958HIGH lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. | Oct 2, 2017 | 7.2 | 23 | NO | NO |
CVE-2017-9332MEDIUM The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag. | Jun 6, 2017 | 6.1 | 21 | NO | NO |
CVE-2015-5458MEDIUM Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter. | Jul 8, 2015 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotx.
Media articles that mention a CVE ID that affects a product developed by Pivotx — matched by CVE ID, not by vendor name.