Pulsecms develops a content management system that has drawn attention within the vulnerability landscape despite a narrow product scope, with its security exposure concentrating around input handling and access control. The vendor's recurring vulnerability classes—including path traversal, cross-site scripting, code injection, and cross-site request forgery—reflect common weaknesses in web application frameworks where user input validation and output encoding are critical. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pulsecms over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4330MEDIUM Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) | Dec 7, 2010 | 6.8 | 34 | NO | YES |
CVE-2011-5041MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action | Dec 30, 2011 | 4.3 | 25 | NO | YES |
CVE-2010-0992MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote attackers to hijack the authenticat | Apr 9, 2010 | 6.8 | 19 | NO | NO |
CVE-2010-0993MEDIUM Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allows remote authenticated users to execute arbitrary code by uploa | Apr 9, 2010 | 6.0 | 18 | NO | NO |
CVE-2010-1334MEDIUM Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followe | Apr 9, 2010 | 6.0 | 17 | NO | NO |
CVE-2010-0988MEDIUM Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper | Mar 26, 2010 | 6.0 | 17 | NO | NO |
CVE-2010-0989MEDIUM Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f par | Mar 26, 2010 | 5.5 | 16 | NO | NO |
CVE-2010-1298MEDIUM Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter. NOTE: the pr | Apr 6, 2010 | 4.0 | 14 | NO | NO |
CVE-2010-1080MEDIUM Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter. | Mar 23, 2010 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pulsecms.
Media articles that mention a CVE ID that affects a product developed by Pulsecms — matched by CVE ID, not by vendor name.