Siberiancms
Siberiancms is a narrowly scoped content-management system that serves a more prominent role in its niche than its modest product count suggests, with vulnerabilities concentrated in a single primary product. The exposure skews strongly toward critical-severity outcomes and recurs through application-layer weakness classes including cross-site scripting, SQL injection, improper access control, code injection, and privilege-handling flaws that are characteristic of web-facing CMS platforms. Defenders deploying this system should treat security updates as high-priority given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Siberiancms over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39375CRITICAL
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
| Sep 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-41702CRITICAL SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Jul 30, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-1105MEDIUM A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of | Feb 7, 2025 | 6.1 | 24 | NO | NO |
CVE-2023-39378HIGH SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user | Sep 27, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-39377HIGH SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecif | Sep 27, 2023 | 7.2 | 23 | NO | NO |
CVE-2017-6906MEDIUM An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/ | Mar 15, 2017 | 6.1 | 22 | NO | NO |
CVE-2023-39376MEDIUM
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
| Sep 27, 2023 | 6.5 | 18 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (7 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Siberiancms.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Siberiancms — matched by CVE ID, not by vendor name.