Setucocms Project maintains a focused content-management system with a vulnerability profile concentrated in a single product and recurrent across application-layer input-handling and access-control weaknesses. The exposure centers on cross-site request forgery, code injection, cross-site scripting, and SQL injection, reflecting the common attack surface of web-based CMS platforms where user-supplied input flows through template generation and database queries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Setucocms Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4893HIGH SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Apr 12, 2017 | 8.8 | 27 | NO | NO |
CVE-2016-4891HIGH Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecifi | Apr 12, 2017 | 8.8 | 27 | NO | NO |
CVE-2016-4896MEDIUM SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors. | Apr 12, 2017 | 6.5 | 22 | NO | NO |
CVE-2016-4895HIGH SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors. | Apr 12, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-4892MEDIUM Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 12, 2017 | 6.1 | 21 | NO | NO |
CVE-2016-4894MEDIUM SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors. | Apr 12, 2017 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Setucocms Project.
Media articles that mention a CVE ID that affects a product developed by Setucocms Project — matched by CVE ID, not by vendor name.