Tilde CMS Project maintains a modestly represented content management system where the vulnerability footprint centers on the core Tilde CMS product and recurs through information-disclosure issues, SQL injection, and unsafe file-upload handling—weaknesses typical of web applications that process user-supplied content and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tilde Cms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11324CRITICAL An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerab | Jul 24, 2017 | 9.8 | 24 | NO | NO |
CVE-2017-11326HIGH An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation. | Jul 24, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-11325HIGH An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php. | Jul 24, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-11327MEDIUM An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content | Jul 24, 2017 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tilde Cms Project.
Media articles that mention a CVE ID that affects a product developed by Tilde Cms Project — matched by CVE ID, not by vendor name.