Sdcms is a focused content management system with a modest vulnerability footprint centered on its core platform product. Its durable signal reflects application-layer security weaknesses, including cross-site request forgery, code injection, and path-traversal flaws that commonly affect web-based administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sdcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19520HIGH An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functions such as eval, but | Nov 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2019-9651CRITICAL An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. T | Mar 11, 2019 | 9.8 | 25 | NO | NO |
CVE-2018-19748HIGH app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index&p=attachment&root= directory traversal. The value of t | Nov 29, 2018 | 7.5 | 24 | NO | NO |
CVE-2019-9652HIGH There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t | Mar 11, 2019 | 8.8 | 22 | NO | NO |
CVE-2018-11004HIGH An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remote attackers to add administrato | May 12, 2018 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sdcms.
Media articles that mention a CVE ID that affects a product developed by Sdcms — matched by CVE ID, not by vendor name.