Sunlight CMS is a narrowly scoped content-management system with a focused vulnerability footprint centered on the single product line. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sunlight Cms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2774HIGH Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or ( | May 21, 2007 | 7.5 | 29 | NO | YES |
CVE-2023-48202MEDIUM Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager compone | Jan 27, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-48201MEDIUM Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to th | Jan 27, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sunlight Cms.
Media articles that mention a CVE ID that affects a product developed by Sunlight Cms — matched by CVE ID, not by vendor name.