Runcms is a modestly represented content management and community platform whose vulnerability footprint spans a focused product line including its core CMS, classifieds module, article management, forums, and photo galleries. The vendor's disclosures cluster around application-layer input-handling weaknesses, prominently featuring SQL injection, code injection, and cross-site scripting across its web-facing components, which reflects the parsing and output-encoding demands of dynamic content systems. A notable characteristic of this vendor's profile is the frequent availability of public exploit code for its vulnerabilities, consistent with the appeal of CMS platforms as targets for mass-exploitation campaigns and defacement. Defenders should prioritize patching this vendor's releases promptly and monitor for indicators of exploitation in web logs and administrative activity, as disclosures here tend to acquire tooling enabling opportunistic attacks; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Runcms over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3354HIGH Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the | Jul 28, 2008 | 7.5 | 32 | NO | YES |
CVE-2008-0878HIGH SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a vi | Feb 21, 2008 | 7.5 | 32 | NO | YES |
CVE-2007-2539HIGH The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors. | May 9, 2007 | 7.8 | 32 | NO | YES |
CVE-2007-6548HIGH Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code via the (1) header and (2) foote | Dec 28, 2007 | 7.5 | 31 | NO | YES |
CVE-2007-2538HIGH SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array param | May 9, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-6544HIGH Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, o | Dec 28, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-1793HIGH Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forum | Apr 17, 2006 | 7.6 | 29 | NO | YES |
CVE-2009-2591HIGH SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to | Jul 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-2084HIGH SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a l | May 5, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1551HIGH SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Mar 31, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Runcms.
Media articles that mention a CVE ID that affects a product developed by Runcms — matched by CVE ID, not by vendor name.