Popojicms is a content management system with a modestly represented vulnerability footprint that reflects the typical attack surface of web-based administrative platforms. Its disclosures cluster around input-handling and access-control weaknesses—including cross-site request forgery, cross-site scripting, path traversal, unrestricted file uploads, and resource exposure—that are characteristic of web application flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Popojicms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18934CRITICAL An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a Z | Nov 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2022-47766HIGH PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability. | Jan 19, 2023 | 8.8 | 28 | NO | NO |
CVE-2018-18935HIGH An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account. | Nov 5, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-18936HIGH An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=d | Nov 5, 2018 | 7.5 | 25 | NO | NO |
CVE-2024-58284HIGH PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoin | Dec 10, 2025 | 7.2 | 24 | NO | NO |
CVE-2020-19547MEDIUM Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php. | Aug 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2019-9549HIGH An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-201 | Mar 3, 2019 | 8.8 | 22 | NO | NO |
CVE-2020-21357MEDIUM A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload | Aug 6, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-18816MEDIUM po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS. | Nov 7, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-18815MEDIUM PopojiCMS 2.0.1 allows refer= Open Redirection. | Nov 7, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Popojicms.
Media articles that mention a CVE ID that affects a product developed by Popojicms — matched by CVE ID, not by vendor name.