Westboy maintains a narrowly scoped product line centered on the Cicada CMS platform, which despite modest vulnerability volume commands attention due to its concentration of serious-severity outcomes. The recurring vulnerability profile reflects web-application and code-execution characteristics: code injection, cross-site scripting, SQL injection, input-validation flaws, and unsafe deserialization issues that are endemic to content-management systems and can escalate quickly in internet-facing deployments. Defenders should prioritize patching this vendor's releases and audit instances for exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Westboy over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1556CRITICAL A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Temp | Feb 22, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3585HIGH A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of | Apr 14, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-3816HIGH A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Tas | Apr 19, 2025 | 7.2 | 22 | NO | NO |
CVE-2025-2624HIGH A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/cms/content/save. The m | Mar 22, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-11289MEDIUM A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao | Oct 5, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-11068MEDIUM A vulnerability was found in westboy CicadasCMS 1.0. Affected by this vulnerability is an unknown functionality of the file /system/cms/category/save. The manipulation of the argum | Sep 27, 2025 | 4.8 | 19 | NO | NO |
CVE-2025-11069MEDIUM A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. | Sep 27, 2025 | 4.8 | 18 | NO | NO |
CVE-2025-2623MEDIUM A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content | Mar 22, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-2625MEDIUM A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument | Mar 22, 2025 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Westboy.
Media articles that mention a CVE ID that affects a product developed by Westboy — matched by CVE ID, not by vendor name.