Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Runcms

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 34
45.1
VTI Score
High

Runcms is a modestly represented content management and community platform whose vulnerability footprint spans a focused product line including its core CMS, classifieds module, article management, forums, and photo galleries. The vendor's disclosures cluster around application-layer input-handling weaknesses, prominently featuring SQL injection, code injection, and cross-site scripting across its web-facing components, which reflects the parsing and output-encoding demands of dynamic content systems. A notable characteristic of this vendor's profile is the frequent availability of public exploit code for its vulnerabilities, consistent with the appeal of CMS platforms as targets for mass-exploitation campaigns and defacement. Defenders should prioritize patching this vendor's releases promptly and monitor for indicators of exploitation in web logs and administrative activity, as disclosures here tend to acquire tooling enabling opportunistic attacks; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Runcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jul 25, 2010
5,843 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3354HIGH
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the
Jul 28, 20087.532NOYES
CVE-2008-0878HIGH
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a vi
Feb 21, 20087.532NOYES
CVE-2007-2539HIGH
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors.
May 9, 20077.832NOYES
CVE-2007-6548HIGH
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) foote
Dec 28, 20077.531NOYES
CVE-2007-2538HIGH
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array param
May 9, 20077.530NOYES
CVE-2007-6544HIGH
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, o
Dec 28, 20077.529NOYES
CVE-2006-1793HIGH
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forum
Apr 17, 20067.629NOYES
CVE-2009-2591HIGH
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to
Jul 24, 20097.528NOYES
CVE-2008-2084HIGH
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a l
May 5, 20087.528NOYES
CVE-2008-1551HIGH
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Mar 31, 20087.528NOYES
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
47%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown34 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown34 (100.0%)
User Interaction
None0 (0.0%)
Unknown34 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown34 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
22 CVEs
64.7% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Runcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Runcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Runcms's Products

View all 1 CNAs →

Top CWEs