Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tuzitio

First CVE: Oct 15, 2018Active for: 8 yearsTotal CVEs: 11
50.1
VTI Score
TOP TARGET

Tuzitio develops Camaleon CMS, a web content management system whose vulnerability profile skews toward serious outcomes with a notable share reaching critical severity and frequent public exploit availability. The exposure recurs through application-layer weakness classes including cross-site scripting, path traversal, code injection, and improper handling of exceptional conditions, all characteristic of web frameworks that process and render user-supplied content. Defenders should track this vendor's releases for exposed CMS instances and prioritize input-validation and sanitization patches; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tuzitio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 15, 2018
7 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-30145CRITICAL
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
May 26, 20239.865NOYES
CVE-2024-46986CRITICAL
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaControll
Sep 18, 20249.959NOYES
CVE-2024-46987HIGH
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file metho
Sep 18, 20247.754NOYES
CVE-2021-25970HIGH
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have
Oct 20, 20218.827NONO
CVE-2026-1776MEDIUM
Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users t
Mar 10, 20266.524NONO
CVE-2021-25969MEDIUM
In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the
Oct 20, 20216.121NONO
CVE-2018-18260MEDIUM
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?ac
Oct 15, 20186.121NONO
CVE-2023-53936MEDIUM
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can cre
Dec 18, 20254.818NONO
CVE-2021-25972MEDIUM
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from ext
Oct 20, 20214.918NONO
CVE-2021-25971MEDIUM
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access u
Oct 20, 20214.317NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
18%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low4 (36.4%)
High3 (27.3%)
None4 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
18.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tuzitio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tuzitio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tuzitio's Products

View all 4 CNAs →

Top CWEs