Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

S Cms

First CVE: Oct 17, 2018Active for: 8 yearsTotal CVEs: 84

S CMS is a content management system that occupies a niche but prominent position in the vulnerability landscape, with its disclosures concentrated in the product itself and its enterprise website construction variant. The vendor's vulnerability footprint remains modest in absolute terms while commanding attention within its application category, driven by the web-facing nature and user-administration scope of CMS platforms. Specific weakness patterns have not yet coalesced into a durable recurring profile across its disclosures, and defenders should monitor emerging update advisories to establish mitigation cadence as the product's threat model clarifies. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by S Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2018
7 years ago
Most Recent CVE
Jan 4, 2024
932 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10708CRITICAL
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
Apr 2, 20199.832NONO
CVE-2021-37270CRITICAL
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified backgroun
Sep 27, 20219.831NONO
CVE-2018-20480CRITICAL
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.
Dec 26, 20189.831NONO
CVE-2018-20477CRITICAL
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.
Dec 26, 20189.831NONO
CVE-2018-18887CRITICAL
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
Nov 1, 20189.831NONO
CVE-2022-23336CRITICAL
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
Feb 14, 20229.830NONO
CVE-2019-6805CRITICAL
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
Jan 25, 20199.830NONO
CVE-2023-51049CRITICAL
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.
Dec 21, 20239.829NONO
CVE-2018-20479CRITICAL
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.
Dec 26, 20189.829NONO
CVE-2018-18427CRITICAL
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
Oct 17, 20189.829NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network42 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None26 (61.9%)
Unknown0 (0.0%)
Required16 (38.1%)
Privileges Required
Low8 (19.0%)
High5 (11.9%)
None29 (69.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by S Cms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by S Cms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For S Cms's Products

View all 2 CNAs →

Top CWEs