Tuzitio develops Camaleon CMS, a web content management system whose vulnerability profile skews toward serious outcomes with a notable share reaching critical severity and frequent public exploit availability. The exposure recurs through application-layer weakness classes including cross-site scripting, path traversal, code injection, and improper handling of exceptional conditions, all characteristic of web frameworks that process and render user-supplied content. Defenders should track this vendor's releases for exposed CMS instances and prioritize input-validation and sanitization patches; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tuzitio over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30145CRITICAL Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | May 26, 2023 | 9.8 | 65 | NO | YES |
CVE-2024-46986CRITICAL Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaControll | Sep 18, 2024 | 9.9 | 59 | NO | YES |
CVE-2024-46987HIGH Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file metho | Sep 18, 2024 | 7.7 | 54 | NO | YES |
CVE-2021-25970HIGH Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have | Oct 20, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-1776MEDIUM Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users t | Mar 10, 2026 | 6.5 | 24 | NO | NO |
CVE-2021-25969MEDIUM In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the | Oct 20, 2021 | 6.1 | 21 | NO | NO |
CVE-2018-18260MEDIUM In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?ac | Oct 15, 2018 | 6.1 | 21 | NO | NO |
CVE-2023-53936MEDIUM Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can cre | Dec 18, 2025 | 4.8 | 18 | NO | NO |
CVE-2021-25972MEDIUM In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from ext | Oct 20, 2021 | 4.9 | 18 | NO | NO |
CVE-2021-25971MEDIUM In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access u | Oct 20, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tuzitio.
Media articles that mention a CVE ID that affects a product developed by Tuzitio — matched by CVE ID, not by vendor name.