Cuppacms

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 25
    Known Exploited: 0
    8
    Critical Level Threats
    12
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-47990

    SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

    Last Modified: Nov 21, 2024
    Published: Dec 20, 2023

    CVE-2023-39681

    Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

    Last Modified: Nov 21, 2024
    Published: Sep 05, 2023

    CVE-2021-29368

    Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.

    Last Modified: Apr 03, 2025
    Published: Jan 20, 2023

    CVE-2022-37191

    The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

    Last Modified: Nov 21, 2024
    Published: Sep 13, 2022

    CVE-2022-37190

    CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

    Last Modified: Nov 21, 2024
    Published: Sep 13, 2022
    Items Per Page
    Cuppacms Vulnerabilities & Security CVEs | CVE-DB