Pyrocms is a content management system that, despite a narrow product footprint, occupies a visible niche in web-application deployments and carries a notable vulnerability burden. Its disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with exposure concentrated around classic web-application weaknesses including cross-site scripting, cross-site request forgery, and input-handling flaws that arise in template-driven CMS architectures. Defenders running this platform should prioritize patch deployment and monitor for exploitation activity, as live severity and exploit-availability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyrocms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29689CRITICAL PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious a | Aug 4, 2023 | 9.8 | 59 | NO | YES |
CVE-2022-37721CRITICAL PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading | Nov 25, 2022 | 9.0 | 31 | NO | NO |
CVE-2022-35118MEDIUM PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | Aug 1, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-25263HIGH PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted. | Oct 8, 2020 | 7.1 | 22 | NO | NO |
CVE-2024-58297MEDIUM PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a p | Dec 11, 2025 | 5.4 | 20 | NO | NO |
CVE-2020-25262MEDIUM PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted. | Oct 8, 2020 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyrocms.
Media articles that mention a CVE ID that affects a product developed by Pyrocms — matched by CVE ID, not by vendor name.