Weaselcms Project maintains a focused content-management system product with a narrow but moderately deployed footprint, where the recurring vulnerability signal centers on application-layer input handling and file-upload controls, specifically cross-site request forgery, cross-site scripting, and unrestricted file-upload weaknesses. These patterns reflect the classic risks of web-based CMS platforms that accept user input and manage file assets without sufficient input validation and request authenticity controls. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weaselcms Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16352CRITICAL There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used. | Sep 2, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14959HIGH An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. | Aug 5, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-14958HIGH An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php. | Aug 5, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-17361MEDIUM Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishan | Sep 23, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-14877MEDIUM An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page. | Aug 3, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weaselcms Project.
Media articles that mention a CVE ID that affects a product developed by Weaselcms Project — matched by CVE ID, not by vendor name.