Xcms is a niche content management system whose vulnerability footprint centers on application-layer web and code-execution risks spanning cross-site request forgery, code injection, and path-traversal weaknesses. These weakness classes reflect typical exposure vectors for CMS platforms handling user input and file management; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xcms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6652HIGH cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute a | Jan 4, 2008 | 7.5 | 29 | NO | YES |
CVE-2007-6604MEDIUM Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the a | Dec 31, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-5060MEDIUM Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain | Sep 24, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xcms.
Media articles that mention a CVE ID that affects a product developed by Xcms — matched by CVE ID, not by vendor name.