Teacms Project maintains a focused content-management system that, despite a narrow product scope, has drawn attention as a higher-profile target in the vulnerability landscape. Its disclosures cluster around web-application input-handling and access-control weaknesses—including cross-site scripting, cross-site request forgery, SQL injection, path traversal, and improper authentication—that are characteristic of CMS platforms and skew toward serious outcomes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teacms Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1483CRITICAL A vulnerability has been found in XiaoBingBy TeaCMS up to 2.0.2 and classified as critical. This vulnerability affects unknown code of the file /admin/getallarticleinfo. The manipu | Mar 18, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-1398HIGH A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation le | Mar 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-27091HIGH An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s). | Apr 4, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-1616MEDIUM A vulnerability was found in XiaoBingBy TeaCMS up to 2.0.2. It has been classified as problematic. Affected is an unknown function of the component Article Title Handler. The manip | Mar 24, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-27090MEDIUM Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via the article title parameter. | Apr 20, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-5033MEDIUM A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/contr | May 21, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teacms Project.
Media articles that mention a CVE ID that affects a product developed by Teacms Project — matched by CVE ID, not by vendor name.