Puppycms is a content management system whose disclosed vulnerabilities center on web-application input handling and access control, with the durable signal pointing to cross-site scripting, cross-site request forgery, improper input neutralization, and authorization weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Puppycms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-18890CRITICAL Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php. | May 6, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-18889MEDIUM Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php. | May 6, 2021 | 6.5 | 21 | NO | NO |
CVE-2018-15847MEDIUM An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field. | Aug 25, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-18888HIGH Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. | May 6, 2021 | 7.5 | 19 | NO | NO |
CVE-2022-3464MEDIUM A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_ | Oct 12, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Puppycms.
Media articles that mention a CVE ID that affects a product developed by Puppycms — matched by CVE ID, not by vendor name.