Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-50937

    Ametys CMS v4.4.1 - Cross Site Scripting (XSS)

    Last Modified: Apr 07, 2026
    Published: Jan 13, 2026

    CVE-2024-30614

    An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

    Last Modified: Apr 11, 2025
    Published: Apr 12, 2024

    CVE-2022-26159

    The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

    Last Modified: Nov 21, 2024
    Published: Feb 28, 2022

    CVE-2017-16935

    Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.

    Last Modified: Apr 20, 2025
    Published: Nov 24, 2017
    Items Per Page
    Ametys Vulnerabilities & Security CVEs | CVE-DB