Couchcms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47955

    CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload

    Last Modified: May 18, 2026
    Published: May 16, 2026

    CVE-2021-47958

    CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload

    Last Modified: May 15, 2026
    Published: May 15, 2026

    CVE-2026-29002

    CouchCMS Privilege Escalation via f_k_levels_list Parameter

    Last Modified: Apr 16, 2026
    Published: Apr 10, 2026

    CVE-2025-67004

    ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /\<file> is accessible it is a web-server configuration issue.

    Last Modified: Jan 23, 2026
    Published: Jan 09, 2026

    CVE-2025-15005

    CouchCMS reCAPTCHA config.example.php hard-coded key

    Last Modified: Feb 24, 2026
    Published: Dec 22, 2025
    Items Per Page