Rgcms Project maintains a focused content management system product where the observed vulnerability surface centers on web-application input-handling and file-upload controls, reflected in recurring issues such as cross-site scripting and unrestricted file uploads. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rgcms Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21481HIGH An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file. | Sep 15, 2021 | 7.2 | 24 | NO | NO |
CVE-2020-21480HIGH An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file. | Sep 15, 2021 | 7.2 | 24 | NO | NO |
CVE-2020-21482MEDIUM A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board modu | Sep 15, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rgcms Project.
Media articles that mention a CVE ID that affects a product developed by Rgcms Project — matched by CVE ID, not by vendor name.